I use the Dynamic Device & OS Identification for addresses and it works great, BUT it only works for IPv4 as far as I can see. You can define an address by MAC address in both IPv4 and IPv6 but you can't create a Dynamic address in IPv6 based on Device or OS. Why is this missing? Its a very helpful feature in IPv4. Is there a workaround?
I'm on 7.4.8
Hi ameif56hgt,
Currently, the dynamic Device & OS Identification feature is not available for IPv6 addresses on FortiGate firewalls, as it relies on protocols associated with IPv4.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPv6-support/ta-p/195325
Regards,
Thanks. I kinda figured that, but the question is why? If you click on the dynamic IPv4 address that is created, you get a list of MAC addresses of devices that are matched for that device. Also you can create a IPv6 address composed of a MAC address currently, just like in IPv4, so its seems quite shortsighted that this doesn't work with IPv6. I guess yet another feature that doesn't fully support IPv6.
User | Count |
---|---|
2624 | |
1393 | |
804 | |
670 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.