Skip to main content
sreddi
Staff
Staff
February 10, 2020

Technical Tip: How to enable interface pair view

  • February 10, 2020
  • 0 replies
  • 42962 views

Description

 

This article describes how to enable interface pair view when it is greyed out.

 

Scope

 

FortiGate.


Solution

 

Before v7.4, if Policies with 'any' or 'multiple interfaces' are selected in the incoming or outgoing interface, 'Interface pair view' will be disabled. Starting from v7.4.0, 'Interface Pair View' will not be greyed out.

Remove 'Any' or 'multiple interfaces' from the policy to select 'Interface Pair View'.

 

JeanPhilippe_P_0-1727967272993.png

 

There are also specific cases when the Interface Pair View it is shown as greyed out. 

One of these cases is the usage of SD-WAN and zones. When different zones are created on the SD-WAN and apply 2 or more of them as sources or destinations on the firewall policies, the Interface Pair View will be grayed out, as it is expected.

 

MigenaM_0-1677507900395.png

 

Below the three zones, part of the SD-WAN is configured as dstintf on the Test_Policy, and as seen, the Interface Pair View it is grayed out:

 

MigenaM_2-1677508164817.png

 

In the case mentioned above, to be able to enable Interface Pair View again, the solution is to create separate firewall policies for each zone set as dstintf (destination interface):

 

MigenaM_3-1677508593780.png

 

As seen, the Interface Pair View has not grayed out anymore and can be selected.

 

Note:

Interface Pair View does not support explicit web proxy policy since v7.4.4 and v7.6.0. Implicit Deny policy is exempted from this behavior. 

 

Related article: 

Technical Tip: Firewall policy views

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!