Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
chrbar
New Contributor

Firewall Rules on Device Objects ?

Hello, We can create Device Objects with MAC Address information. Can we use these Device Objects inside a Firewall rule, to deny Internet access? I've created a Device and added it into Authentication of a rule that deny FTP/HTTP/HTTPS Services to Internet. But this rule doesn't catch this device Internet browsing. Do I have to install the FortiClient on this device to be able to use Device Objects into Firewall rules? Regards, Chris

 

 

1 REPLY 1
Jeff_FTNT
Staff
Staff

You may just enable "device-identification"  on interface, FGT will detect MAC/OS information.

config system interface     edit "port11"         set device-identification enable end

 

Add  "device-group"  to policy .

Some diag CLI : # dia user device xxx,

Hope is helpful, thanks

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors