Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
digimetrica
New Contributor

unauthuser and "fixed" mac address bind

Hello,

 

My FGTs (two different models with latest firmware) are logging with a strange behaviour:

All traffic from every public IP toward different servers in DMZ are logging with the same MAC address. I don't know if it is some ISP device before the firewall. Fortigate BINDS this ip to the first logging user (to a mail server ie) and EVERY IP connecting has that user as an "unathenticated user".

This kind of traffic has NOTHING to do with that user but it keeps match that first login MAC Address to that user.

 

This thing is driving me crazy because I have weird and not trustworthy reporting (having an user doing 98% of my traffic is something not affordable :))

 

i opened a ticket and the reply was the default pre-constructed answer: "check your mail system, etc etc", this has nothing to do with mail servers.

 

I suspect it is the option in the network port "detect and identify devices". I just disabled and i will let you know

1 REPLY 1
digimetrica
New Contributor

it's confirmed: it was that option on network interface that forces FGT to look at a MAC-address <-> user match

Labels
Top Kudoed Authors