Skip to main content
tahmadov
Staff
Staff
November 8, 2019

Technical Tip: How to allow the configuration of policies with multiple source/destination interfaces or 'any'

  • November 8, 2019
  • 0 replies
  • 50571 views

Description

 

This article describes how to enable the configuration of policies with multiple source/destination interfaces or 'any' through GUI and CLI.

Useful Links:
Feature visibility

 

Scope

 

FortiGate.

Solution

 
To enable the feature through the GUI:
 
Go to System -> Feature Visibility and, under the Additional Features, allow the Multiple Interface Policies and then select Apply.
 
Stephen_G_0-1725281557057.png
 
To enable the feature through the CLI:
 
config system settings
set gui-multiple-interface-policy enable
end
 
After enabling the feature, adding multiple interfaces or 'any' in a firewall policy on the GUI is allowed. When choosing 'any', adding of additional interface is no longer possible as it implies that all interfaces have already been selected. 
 
Stephen_G_1-1725281610412.png


Note:

On v7.0.x, v7.2.x putting multiple incoming/outgoing interfaces or using 'any' interface will cause the 'Interface Pair View' to be greyed out as shown below. 

 

IPV.PNG

 

Starting from v7.4, 'Interface Pair View' will not be greyed out as shown below:

 

MultipleInterface.png

 

Related articles: 

 

Related video: