Hello, running a Transparent VDOM with a single VWP between a Cisco L3 and ASA, my question is why do I only see a single device from the traffic coming thru the switch -- I assume its a L3 Source MAC change? Is my only option here to install FortiClient? I don't control the Cisco setup and am just tasked with getting device info. I have Device Detection turned on.
Yes your assumptions is correct that src_mac is probably the l3 device. SInce this masking all of the devices, I don't know how you could do device detection.
Also, what would expect to achieve if it's one and one src_mac
Ken
PCNSE
NSE
StrongSwan
Hi have you got a diagram / screen shots of the setup?
What about the IP sessions in FortiView? Do you see multiple source/destination IP addresses?
Here is a video to explain how to setup logging https://video.fortinet.com/video/228/cookbook-logging-traffic-and-using-fortiview-5-4 about 2:45 into the video shows how to monitor IP sessions
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.