- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does Fortigate have any MAC Security features?
Hi,
Is there any rule or feature that can be used to enforce security for MAC addresses?
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello
Sure!
FortiGate has a built in NAC, where you can specify MAC address in NAC policy.
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/830632/nac
On the other hand FortiGate can use MAC addresses as address objects in your firewall rules if needed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello
You can also configure sticky MAC address. Protect the switch and the whole network when combined with MAC-learning-limit against security attacks such as Layer 2 DoS and overflow attacks.
https://docs.fortinet.com/document/fortigate/6.2.0/new-features/485133/mac-address-based-policies
Regards
Verender
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you very much @KumarV. Please could you tell me if device detection must be enable on every interface to enforce MAC address-based IPV4 policies? The article does not explain this but the one below from salemneaz does require device detection to be enabled.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, you can create MAC address filter at the FortiGate, take a look at the article reference given below;
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi jefazo92,
not sure if it applies to your environment but you might also be interested in MAC address check for remote hosts connecting through sslvpn.
Aside from OS and Host check, FortiGate can also perform a MAC address check on the remote host.
Regards
