Helpful ReplyHot!Fortigate interfaces mac address changed

Author
BensonLEI
Bronze Member
  • Total Posts : 54
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/06/01 21:08:14
  • Status: offline
2020/10/22 19:46:01 (permalink)
0

Fortigate interfaces mac address changed

Hi guys, 
 
We have Forti400E HA pairs topology ( with FortiOS V6.4.2 ) in the production network, and intend to change the interface MAC add; do we need to change the same mac add for both devices at the same time, or just change the MAC add in primary/master Forti400E ( it will synch the mac add to the secondary/slave Forti400E ) ?
 
Thanks so much for your advice
 
 
#1
MarMar
New Member
  • Total Posts : 2
  • Scores: 1
  • Reward points: 0
  • Joined: 2020/10/23 00:10:33
  • Status: offline
Re: Fortigate interfaces mac address changed 2020/10/23 05:32:41 (permalink) ☄ Helpfulby BensonLEI 2020/10/26 19:18:46
4 (1)
Hi,
 
Every FortiGate physical interface has two MAC addresses: the current hardware address and the permanent hardware address. The permanent hardware address cannot be changed, it is the actual MAC address of the interface hardware. The current hardware address can be changed.
 
For an operating cluster, the current hardware address of each cluster unit interface is changed to the HA virtual MAC address by the FGCP. The macaddr option is not available for a functioning cluster. You cannot change an interface MAC address and you cannot view MAC addresses from the system interface CLI command.
 
MarMar
#2
boneyard
Gold Member
  • Total Posts : 364
  • Scores: 16
  • Reward points: 0
  • Joined: 2014/07/30 11:15:18
  • Status: offline
Re: Fortigate interfaces mac address changed 2020/10/23 06:53:48 (permalink) ☄ Helpfulby BensonLEI 2020/10/27 03:23:20
0
how are you going to change the MAC address?
 
if this is based on the group-id in the ha settings i believe this needs to be done on both units.
 
if in another way please share how.
#3
BensonLEI
Bronze Member
  • Total Posts : 54
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/06/01 21:08:14
  • Status: offline
Re: Fortigate interfaces mac address changed 2020/10/26 19:18:52 (permalink)
0
Hi, MARMAR,
 
Thanks so much for your information.
 
Based on my finding, two mac addr are defined for a fortigate interface ( current and perm. mac add), as you state.
 
But the current mac add can be viewed and changed:
 
https://kb.fortinet.com/kb/documentLink.do?externalID=FD30888.
 
 
Cheers
 
 
 
 
#4
MarMar
New Member
  • Total Posts : 2
  • Scores: 1
  • Reward points: 0
  • Joined: 2020/10/23 00:10:33
  • Status: offline
Re: Fortigate interfaces mac address changed 2020/10/27 02:11:38 (permalink) ☄ Helpfulby BensonLEI 2020/10/27 03:22:38
0
Hi BensonLEI,
 
what you say is true if you are not talking about HA Cluster.
In this case the FGCP (Fortigate Cluster Protocol) manages the current addresses and it is no longer possible to set them manually.
In this part of the documentation it is a bit clearer.
 
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/996579/cluster-virtual-mac-addresses
 
MarMar
#5
BensonLEI
Bronze Member
  • Total Posts : 54
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/06/01 21:08:14
  • Status: offline
Re: Fortigate interfaces mac address changed 2020/10/27 03:22:44 (permalink)
0
Hi, MARMAR,
 
Thanks so much for your information, now I understand.
I am running the Fortigate HA pair,  can I change the Cluster-ID for the different virtual mac add ( any device reboot if the mac add is changed) ? 
 
Cheers
#6
BensonLEI
Bronze Member
  • Total Posts : 54
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/06/01 21:08:14
  • Status: offline
Re: Fortigate interfaces mac address changed 2020/10/27 03:23:49 (permalink)
0
Hi, Boneyard,
 
Great help.
 
Cheers
 
#7
boneyard
Gold Member
  • Total Posts : 364
  • Scores: 16
  • Reward points: 0
  • Joined: 2014/07/30 11:15:18
  • Status: offline
Re: Fortigate interfaces mac address changed 2020/10/31 11:25:00 (permalink)
0
BensonLEI
I am running the Fortigate HA pair,  can I change the Cluster-ID for the different virtual mac add ( any device reboot if the mac add is changed) ? 

yes you can change cluster-id and it will change the virtual MAC, that happens directly after the change.
#8
BensonLEI
Bronze Member
  • Total Posts : 54
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/06/01 21:08:14
  • Status: offline
Re: Fortigate interfaces mac address changed 2020/11/05 01:47:33 (permalink)
0
Correct, thx a lot
#9
Jump to:
© 2020 APG vNext Commercial Version 5.5