Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mmorcali
New Contributor

How to block unknown mac address on fortigate software-switch?

Hi,

 

I create a software-switch and enabled DHCP server on it. I spesified the address range and created ip address assigment rules. I want to block unknown mac address. I added mac address - ip address reservetion. But implict rule action is assign ip. How can i change the ubknown mac address actionb to block?

 

 

 

Ekran görüntüsü 2024-03-08 162203.png

1 Solution
ozkanaltas
Valued Contributor III

Hello @mmorcali ,

 

You can easily change implicit rule behavior with a right click. Do Right-click on the implicit rule, and after that select block options in the action menu. 

 

image.png

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
5 REPLIES 5
ozkanaltas
Valued Contributor III

Hello @mmorcali ,

 

You can easily change implicit rule behavior with a right click. Do Right-click on the implicit rule, and after that select block options in the action menu. 

 

image.png

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
mmorcali

I overlooked it. Thank you

mmorcali

Hello

When dhcp is activated, unknown mac address does not receive ip. It is ok. But when an ip is set in the internal subnet, the device can access the internal network. How do I fix this?

ozkanaltas
Valued Contributor III

Hello @mmorcali ,

 

Actually, this request is about the NAC solution. Because of that, you can't do anything with Fortigate.

 

But if your switch is FortiSwitch, Fortigate provides a basic NAC feature with FortiSwitch.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
mmorcali

Ok.

Thank you

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors