Hi! I would like to ask why my firewall policy reflects only on my phone and not on my laptop, even though they’re in the same group (Semi-restricted) that I created. I blocked or restricted some websites using their MAC addresses, but the restrictions only apply to my phone.”
What's your topology? Run a sniffer and check the source mac of the incoming traffic and make sure it's the same as blocked mac.
Sniffer:
dia sniffer pack any "host x.x.x.x" 6 0 a
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Using-the-FortiOS-built-in-packet-sn...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Packet-capture-sniffer/ta-p/198313
If you have L3 switch between your laptop and FGT, then source mac will be mac address of the switch.
Hi! Here's our topology
ISP -- > FORTINET <-- ACCESS POINT --> USER
Until now, I am struggling configuring this firewall, I don't know why the firewall policy only reflects on my phone but not on my laptop even though they're both in the same group
The description of your issue is a little too vague.
Is the same firewall policy matched by both devices? if not, check the difference between policies.
Check the session list and filter by source IP for both devices Troubleshooting Tip: FortiGate session table information
"I blocked or restricted some websites" > how/which security profie? which websites? which browsers? how is the policy configured flow/proxy? deep inspection or certificate?
There are too many variables to consider.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.