cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Community Helping Community

1020
Views
0
Helpful
1
Replies
Highlighted
Beginner

Cisco SG300 vlans with Fortigate 90D

I need help in setting up my network, currently I have the following setup.

NET.jpg

 

All the computers can browse the internet but when I tried to create a two groups (a group that can access the internet and a group that can't access the internet) using Device MAC Access Control but to no avail still all the computers can access the internet. I follow the instructions in the Fortigate Cookbook (FORTI OS 5.4), Fortigate seems cannot recognize/identify MAC Addreses of the computers int the network.

Everyone's tags (4)
1 REPLY 1
VIP Advocate

Re: Cisco SG300 vlans with Fortigate 90D

Hi, 

As I am getting your point, This is happening due to routing on your core switch (default behavior). Due to routing, you are switching will modify L2 header and attaching source mac as self-interface mac address. 

 

try with "no ip proxy-arp" commands under all VLANs or L3 interface on the switch and test it again. 

 

Regards,

Deepak Kumar

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution If this comment will make help you!
CreatePlease to create content
Content for Community-Ad
FusionCharts will render here