Skip to main content
Nivedha
Staff
Staff
February 26, 2024

Technical Tip: Moving an Interface that has existing references to SD-WAN zone using Integrate Interface feature

  • February 26, 2024
  • 0 replies
  • 9566 views

Description

This article describes how to use the integrated interface feature to move the interface that has references to the SD-WAN zone.

Scope

FortiGate v7.x.

Solution

Before FortiGate v7.x:

  • Moving an interface to SD-WAN was a lengthy and manual process.

  • The 'integrate' feature was not available, requiring:

    • Delete all references to the interface (for example: IPSec tunnels and static routes).

    • Move the interface to SD-WAN.

    • Manually recreate all the deleted references.

 

After FortiGate v7.x (using port1 as an example):

  • The process is much simpler and more efficient thanks to the 'integrate' feature.

  • How to move port1 to SD-WAN using the new method:


Note: port1 currently has five references: 

  • Four references across two IPSec tunnels.

  • One reference in a static route.

  • This feature only supports physical interfaces. It is not possible to integrate virtual interfaces such as VLAN and tunnel interfaces. 

 

Prerequisite :

Enable the SD-WAN feature on the firewall before migrating to the default SD-WAN zone.

 

 From CLI:

config system sdwan
    set status enable
end


1.PNG

 

To move the interface to SD-WAN:

 

  1. Select Integrate Interface:


1A.PNG

 

In FortiOS v7.6.x, 'right-click' on the interface and select 'Integrate Interface'. 

II.PNG

 

  1. Select Migrate to SD-WAN zone:

2.PNG

 

  1. Select the SD-WAN zone. 

  2. Check the reference options (replace the instance or delete the entry).

2A.PNG

 

  1. The interface will be moved to the SD-WAN zone.

3.PNG

 

  1. Delete the default static route on port1 and change it to an SD-WAN zone. This is required when multiple interfaces are added to the zone.

4.PNG

 

Note: Migration is not supported if the physical or VLAN interface is used in a tunnel configuration (IPsec or SSL VPN). Instead of deleting and reconfiguring the IPSec tunnel again, change the tunnel binding interface to an unused port. This can be reverted to the original interface after successfully integrating into SD-WAN.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!