HI,
I have experienced a very interesting problem.
I had a network device that was working fine when connected to using a computer or when connected via the FortiGate, however, when connecting via the FortiSwitch it would not work and the FortiSwitch would not even learn the MAC address (The interface was showing up and STP was changed to forwarding state properly).
After long time of troubleshooting i found that the MAC address on that network device could not be found in any OUI database. The manufacture created a new Firmware that corrected the MAC address and i was able to then use it via the FortiSwitch.
I'm trying to understand why the FortiSwitch was blocking it and if there is a log or something i could've seen it getting blocked. I was unable to find any relevant documentation. I'm not using any special security (No NAC, 802.1x authentication etc)
Using fortiswitch 148f-f with firmware 7.6.0
Hi! Can you let me know which device it was?
My company hired a 3rd party company to manufacture a device for us so it's something custom.
A hint to explain (maybe) what happened is the MAC address that didn't work over the FortiSwitch started with A3 (10100011 (binary))
So a multicast and a locally administered address.
The question is how in the future i can see it easily on the FortiSwitch / confirm this is the problem?
I think this should be the standard behavior for all the switches, it can not learn a multicast MAC in a port and should drop the traffic.
I can not test it at the moment but I guess this event will be created 'Corrupt MAC packet detected'.
Bump :)
User | Count |
---|---|
2640 | |
1401 | |
810 | |
686 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.