Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
wws
New Contributor II

Change MAC address for HA'd LAN interface?

We have a pair of FortiGates in an active/passive cluster, and have created a secondary VLAN Interface for VoIP traffic.

We have Netgear switches with Auto-VoIP-VLAN enabled.  This works by matching MAC prefixes.

 

It appears that FortiGates do not allow the MAC address of VLAN Interfaces to be modified, so I've manually configured the primary switch to use port-based VLAN to get the FortiGates and Netgear switches working.  This works, but is not the most ideal solution.

 

So, my question is:  Is there a way to change the MAC address of a VLAN Interface?  Or, is there another type of Interface that would do basic LAN stuff, which would allow me to change its MAC address?

 

Thanks!

2 REPLIES 2
Atul_S
Staff & Editor
Staff & Editor

Hi Wws,

 

Yes, you are right. The VLAN interface will inherit the mac add of the underlay physical port and there is no way to modify the vlan mac add separately. However, pls review the below doc to use emac vlan, which has its unique mac address independent of the physical interface.

 

https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/212317/enhanced-mac-vlan

 

I hope this helps.

 

Thanks,

Atul Srivastava
wws
New Contributor II

@Atul_S 

The HA'd VLAN Switch interface has its own MAC address, which is not based upon the underlying interface(s).  I could still alter the underlying physical ports' MAC addresses, but doing so would have no impact on the switch, as it doesn't "see" those MAC addresses - it only sees the VLAN Switch's virtual MAC address.

 

I did take a peak at the EMAC VLAN, and quickly ran into a major issue with it:  It doesn't have any DHCP server.  I need a fully functional LAN, in active/passive HA, of which I can alter the MAC address.  Everything I've read and tried is leading me to believe this is not possible with FortiGate...

 

I'm hoping someone here can prove me wrong on that.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors