Hi all,
Does any one know a command to show the forwarding table (also known as mac address table) of a software switch or hardware switch on a FortiGate? People reply to this question on similar post with the get system arp but, as the command clearly show, is the arp table (relation between an IP and its MAC address). The forwarding table shows the relation between a port and the mac addresses that are known through it.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Try "diag switch-controller dump mac-hosts-switch-port" (you can have lot more info and other options after "diag switch-controller dump ?".
This will work on Fortigate with ISF (roughly all current and previous generation models afaik).
But it won't give you a straight mac / port forwarding table.
hmiranda wrote:Hi all,
Does any one know a command to show the forwarding table (also known as mac address table) of a software switch or hardware switch on a FortiGate? People reply to this question on similar post with the get system arp but, as the command clearly show, is the arp table (relation between an IP and its MAC address). The forwarding table shows the relation between a port and the mac addresses that are known through it.
FortiOS 5.6 If the operating mode is Transparent then yes, you could use the following command to view the mappings:
diagnose netlink brctl ?
Unfortunately, I don't know how to get this info in case of NAT operation mode.
A side note, in NAT mode, the FGT is working as a layer 3 device & it generally works based on layer-3 information and sometimes replaces/changes the source MAC addresses too from the frames because of the routing purposes.
In case of a virtual switch, some FGTs will create forwarding table. https://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-networking/Interfaces/Virtual%20Swit...
EDIT:
get sys arp command will also show the interface.
Regards,
Prab
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.