Skip to main content
heyyo
Explorer III
October 24, 2024
Question

Fortigate VM default value for allow-traffic-redirect

  • October 24, 2024
  • 3 replies
  • 2090 views

Hi,

 

"For the public Cloud VMs, the status of 'allow-traffic-redirect' is always set to disable due to one-arm traffic." is advised in this KB: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Traffic-handled-by-FortiGate-for-packet-which/ta-p/196651

 

However, looking at my existing configuration for 7.0.12, "allow-traffic-redirect" is currently enabled.

Tried to look at a newly provision VM which is at 7.2.9, "allow-traffic-redirect" is currently disabled.

 

Would you know at which FortiOS version was the default value changed?

My existing configuration was from 6.0

 

Thanks!

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

3 replies

johnathan
Staff
Staff
October 24, 2024

Are you deploying the new VM from a cloud image? You would see the provider (e.g. AWS, Azure, GCP) in the name of the VM image if this is the case. The 'allow-traffic-redirect enable' would not be the default for regular VM images. 

Never trust a computer you can't throw out a window.
pminarik
Staff
Staff
October 24, 2024

It is forced to "disable" by default since 6.4.3/7.0.0 in new deployments. (not listed in release notes, don't waste your time looking for it like I did. :) )