Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
New Contributor III

Showing MAC address on switch with configured Secondary IP on FW



As we have different subnets which are connected to FG's different ports, it's really a huge and mess task to configure the policy set from portA to PortB and with other different ports. So we would like to create a new subnet in a faster way - by using Secondary IP. What we need to do is just add the new subnet address into the group of existing firewall policies, that would be more simplify our workload and would not increase the total no. of policies.


As the Secondary IP method do not segregated the 2 subnets, that means they are connected / communicated on layer 2 level, this is fine and our clients can reached with other subnets via the routing switches ( FW <---> switch <---> switch <--->), actually even no need to configure the VLAN statement for it as our PCs using static IP.


However, the PCs on new subnet could communicate with other subnets now, but from the switch point of view, I cannot trace the MAC address of the PCs... I think all of the PCs are using the same mac address of the secondard IP on FG. This may affecting the network troubleshoot performance.... I even cannot trace which switch the mac address is connected.... does anyone know there is another way to show the PC mac address in switches' arp table? Many thanks!





Protect yourself~ MBCS CEH FCNSA
Protect yourself~ MBCS CEH FCNSA

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Top Kudoed Authors