Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aguerriero
Contributor II

EMAC Duplicate mac address on different firewalls

1500D 7.2.5.

I have two 1500Ds each with an EMAC interface on the same vlan.


What criteria is used to generate the EMAC mac address?

 

Is there a way to change the EMAC mac address or at least control how the address is assigned when the interface is created?

1 Solution
aguerriero

Changing the HA group-id, on the 3 firewall clusters that had default group 0, allowed for unique EMAC mac addresses.

View solution in original post

4 REPLIES 4
AlexC-FTNT
Staff
Staff

Not possible individually, but last example here may cover your requirement:
https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/212317/enhanced-mac-vlan


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
aguerriero
Contributor II

That didn't change the mac.

It looks like the format for the virtual mac device ID is derived in part from group-id in system ha.

00:09:0f:09:<GROUP-ID>:<SOME-OTHER-NUMBER>

Can this be verified by someone?

aguerriero

Changing the HA group-id, on the 3 firewall clusters that had default group 0, allowed for unique EMAC mac addresses.

AlexC-FTNT

Yes, when it comes to clusters, if the virtual mac is used, the cluster ID must be different. This is a requirement for all clusters in a network, but also all clusters added to same security fabric


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
Labels
Top Kudoed Authors