Skip to main content
wmichael
Staff
Staff
April 16, 2025

Troubleshooting Tip: Unable to remove interface from a zone

  • April 16, 2025
  • 0 replies
  • 1248 views
Description

This article discusses the cause of an issue when an interface is unable to be removed from a zone.

Scope FortiGate.
Solution

Under some circumstances, an interface cannot be removed from a zone.

 

Note: This article refers to interface zones and not SD-WAN zones.

 

In this example, there are three zones. Attempting to remove port2 from the Outside zone fails.

 

01-zones.jpg

 

Removing port2 in the GUI:

 

02-port2-removed.jpg

 

No errors are displayed in the GUI, however, port2 remains in the zone.

 

03-port2-not removed.jpg

 

When trying to remove port2 from the zone on the CLI, the following error is observed:

 

Outside is used in policy. port2 can not be removed.

[set_member_to_context_data:4451] node_unset_object(port2) error

 

04-CLI-error.jpg

 

The cause of this issue is that there is a firewall policy using a VIP with port2 as the external interface.

 

VIP using port2 as the external interface:

 

05-VIP.jpg

 

Firewall Policy using the VIP as a destination:

 

06-VIP-in-policy.jpg

 

By removing the VIP from the policy, port2 can successfully be removed from the zone.

 

07-port2-removed-CLI.jpg

 

The GUI no longer displays port2 as part of the zone:

 

08-port2-removed-GUI.jpg

 

For more information about configuring zones, see: Zone.

 

Related articles:

Technical Tip: Virtual IP (VIP) port forwarding configuration

Technical Tip: Pros and Cons of using 'any' for Virtual IP Interface versus a specific interface

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!