Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Hamza_derbali
New Contributor

Issue with MAC Address-Based Policy on VPN Tunnel Interface

Hello,

I'm trying to create a MAC address-based policy using the VPN tunnel interface as the incoming interface, but it's not working and it authorizes all MAC addresses of the VPN users.

 

Do I need a license for this?

Regards,

 

policy mac based.png

1 Solution
ozkanaltas

Hello @Hamza_derbali ,

 

I found a document about that. This document shows you can't apply a mac-based host check with a free client.

 

https://docs.fortinet.com/document/forticlient/7.0.0/new-features/651315/fortigate-powered-host-chec...

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
5 REPLIES 5
ozkanaltas
Valued Contributor II

Hello @Hamza_derbali ,

 

Mac-address-based policy just works on Layer2 networks. Because of that, you can't apply a mac-based policy for SSL-VPN. 

 

Also, I can't see a mac-address object on your screenshot. 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
hbac
Staff
Staff
Hamza_derbali

Hello @hbac ,

Thanks, but I've already seen this article. The issue I'm facing now is determining whether the host checker requires an additional license for accurate information. For your information, I'm using FortiClient 7.2.4.

Regards,

ozkanaltas

Hello @Hamza_derbali ,

 

I found a document about that. This document shows you can't apply a mac-based host check with a free client.

 

https://docs.fortinet.com/document/forticlient/7.0.0/new-features/651315/fortigate-powered-host-chec...

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
hbac

Hi @Hamza_derbali,

 

It is working in my lab. I'm using FortiClient 7.0.9 free version. I configured SSLVPN to deny my MAC address:

Atlantis-kvm60 (full-access) # show
config vpn ssl web portal
edit "full-access"
set tunnel-mode enable
set ipv6-tunnel-mode enable
set ip-mode user-group
set ip-pools "SSLVPN_TUNNEL_ADDR1"
set ipv6-pools "SSLVPN_TUNNEL_IPv6_ADDR1"
set mac-addr-check enable
set mac-addr-action deny
config mac-addr-check-rule
edit "1"
set mac-addr-list 00:53:6d:6f:48:02
next
end
next
endhost.PNG

 

Regards, 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors