Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Julien87
Contributor II

MAC device and source zone

Hi,

 

the feature 'config user device' is removes in the last version 7..

 

Have you an solution to filter sourceIP and MACDevice in one rules ?

 

I have try SourceIP and DeviceMAC object, but this one allow all source network...

 

Best regards

 

Julien
Julien
1 Solution
alif

I guess that's not possible.

The firewall address can be of different types. However, the srcaddr under the firewall policy will allow/deny traffic based on 'OR' basis.

Regards,
SFA

View solution in original post

7 REPLIES 7
alif
Staff
Staff

Hi @Julien87,

 

The command "config user device" has been removed since FortiOS 6.2 version.

 

Please check the below link if it helps.

https://docs.fortinet.com/document/fortigate/6.2.0/new-features/645289/device-detection-label-change...

Regards,
SFA
Julien87
Contributor II

hi @alif

yes i see that. But a solution exist for use mac object address ? For have the same usage ? 

julien 

Julien
Julien
alif

You can define the MAC address in the same way as an IP address.

 

Please select the type "Device (MAC Address)" and mention it in the relevant firewall policy.

https://docs.fortinet.com/document/fortigate/7.0.9/administration-guide/407159/mac-addressed-based-p...

Regards,
SFA
Julien87
Contributor II

Yes, but in my rules i have source network and macdevice object.

how about the rule to indicate network and mac must match to be valid.

 

Actually I have network OR mac for the control of the rule. I would like to have network AND mac address for the check  in my source adresse.

 

Best

 

Regards

 

 

Julien
Julien
alif

I guess that's not possible.

The firewall address can be of different types. However, the srcaddr under the firewall policy will allow/deny traffic based on 'OR' basis.

Regards,
SFA
Julien87
Contributor II

Ok, thanks for your help.

 

just in case, I try a support ticket. I'll let you know here if there's a solution.

 

Have a nice day

 

 

Julien
Julien
Julien87

Hi alif,

 

I just got a return from my case support.
It confirms that there is no AND option.
Moreover it is not planned for later.

 

 

Have a nice day

 

Julien

Julien
Julien
Top Kudoed Authors