Skip to main content
warringaa
New Member
October 30, 2011
Question

Default allow ICMP

  • October 30, 2011
  • 2 replies
  • 4051 views
Is there a way to default allow icmp messages through the whole fortigate firewall? It' s a bit annoying to create default icmp policy rules between every vlan.

    2 replies

    ede_pfau
    SuperUser
    SuperUser
    October 31, 2011
    Hi, and welcome to the forums. ICMP is in no way special compared to other IP traffic. If you want to allow it across interfaces then you have to explicitly allow it in the policy. To make life easier Fortinet gave us the service group object. If you add ICMP or PING to your custom service group that you use in every policy between VLANs then you' re done in a second.
    Paul_Dean
    Visitor III
    November 1, 2011
    If your VLANs will be setup in the same way requiring the same policies you could create a Zone. Add all of your interfaces into the Zone and create a policy of Zone to Zone ICMP allow. Intra-zone traffic is allowed by default.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.