Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

FortiGate sees the same MAC through two ports

Hello FG admins

Could there be any kind of problem if FortiGate in NAT mode sees the same MAC addresses through two independent interfaces?

This is not common at all but can happen when you have for some reason one host with one NIC connected to a L2 switch connected to 2 different interfaces on FG.

AEK
AEK
1 Solution
Toshi_Esumi

If those two ports are independent, they can not have the same subnet. If the IP of the device/MAC matches on p1 side, the p2 side would ignore L2 frames with the MAC arrived at the port. Because it's bound to p1 on the ARP table.

 

Toshi

View solution in original post

11 REPLIES 11
AEK

Tested and confirmed.. Thanks again Toshi.

AEK
AEK
adambomb1219

So a single switch and a single FortiGate.  Why would the firewall ever see two MACs on different ports then?  Is there two downstream links to the single switch?  If so why?  Why aren't these in an aggregate interface instead?

Labels
Top Kudoed Authors