- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to block Unknown Mac Addresses
Hello,
I have a Fortigate 90D. I have been asked by the management to setup policies to block internet access to specific users.
I successfully managed to do this,however, I recently discovered that the users are bypassing the IPv4 Policy by Mac spoofing.
Kindly assist on this.
- Labels:
-
6.0
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can create devices on your fortigate with mac's that you want to allow traffic and then create a policy and set the source with attributes all and the mac's you want to allow.
Orestis Nikolaidis
Network Engineer/IT Administrator
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have already done this. Although some of the users keep changing the Mac address of their devices.
Therefore the policy will not be useful once they change the MAC address
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You may need to do things outside the realm of the firewall like:
[ul]- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Also you can try block through your antivirus programs thatdo mac spoofing
Orestis Nikolaidis
Network Engineer/IT Administrator
