Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why aren't Mac address based policies working normally?
Only pre-registered MAC addresses are allowed to communicate. The policy applies only to accounts and ip addresses and does not follow mac objects.
my rules:
1st.
src : user1, 1.1.1.1, registered_mac_obj(ex. 11:11:11:11:11:11)
dst : all
service : all
action : accept
2nd.
src : user1, 1.1.1.1, un_registered_mac_obj(00:00:00:00:00:00 ~ FF:FF:FF:FF:FF:FF)
dst : all
service : all
action : DENY
At this time, my PC's Mac address is 22:22:22:22:22:22 and belongs to un_registered_mac_obj,
but I still follow the first policy. The reason is unknown.
Labels:
- Labels:
-
FortiGate
1 REPLY 1
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you test the behavior with a policy using only the mac address as match criteria and remove IP/user details (for testing).
Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
