1500D 7.2.5.
I have two 1500Ds each with an EMAC interface on the same vlan.
What criteria is used to generate the EMAC mac address?
Is there a way to change the EMAC mac address or at least control how the address is assigned when the interface is created?
Solved! Go to Solution.
Changing the HA group-id, on the 3 firewall clusters that had default group 0, allowed for unique EMAC mac addresses.
Not possible individually, but last example here may cover your requirement:
https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/212317/enhanced-mac-vlan
That didn't change the mac.
It looks like the format for the virtual mac device ID is derived in part from group-id in system ha.
00:09:0f:09:<GROUP-ID>:<SOME-OTHER-NUMBER>
Can this be verified by someone?
Changing the HA group-id, on the 3 firewall clusters that had default group 0, allowed for unique EMAC mac addresses.
Yes, when it comes to clusters, if the virtual mac is used, the cluster ID must be different. This is a requirement for all clusters in a network, but also all clusters added to same security fabric
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.