Hello Team,
I wanted to know if i have configured my fortigate firewall with source user accounts of user1, user2 and user3, and ip addr1, and ip addr2,and mac addr1, mac addr2, and mac addr3.
How firewall will process the source match logic according to the source objects and type mentioned above User accounts, IP addresses, and mac addresses?
TIA
If you have a user defined in the policy, it based on how you have auth-on-demand set.
Thank you @distillednetwork for the reply and link.
I wanted to know assuming users are authenticated, and with all ojects in the source field mentioned, how the fortios think about source matching?
The AND OR logic among them in matching probability.
It will be User AND IP OR MAC.
The User list is an entire OR list, and the IP/Mac Address address objects will also be an OR list.
Thank you so much, I have made the lab and I wanted to confirm what is the same you've mentioned now, within the type its OR, then ((User account) AND ((IPaddress) OR (Mac address))), and this is according to FortiOS ver 7.4.8 I used for test.
User | Count |
---|---|
2642 | |
1405 | |
810 | |
685 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.