Skip to main content
fat
Visitor III
November 5, 2020
Question

[FortiOS 6.4.2] icmp any any

  • November 5, 2020
  • 2 replies
  • 2914 views

Hello,

 

I have some Fortigate 200E in my lab for testing.

Instead of putting several lines of policy, I use "set srcintf any" and "dstintf any" to configure the icmp policy.

As a result, only one line is enough.

 

In GUI, ANY didn't appear in incoming/outgoing interface, so I did it using CLI.

But after that, the "INTERFACE PAIR VIEW" was unavailable.

 

I'd like to know:

- is it a best practice using ANY instead of selecting a particular interface?

- ANY does appear in another Fortigate with the same firmware and model, why it didn't in this one?

- is it a normal behavior that INTERFACE PAIR VIEW becomes grayed? I found this VIEW helpful sometimes.

 

Thank you for your reply.

 

 

2 replies

lobstercreed
New Member
November 5, 2020

fat wrote:

I'd like to know:

- is it a best practice using ANY instead of selecting a particular interface?

- ANY does appear in another Fortigate with the same firmware and model, why it didn't in this one?

- is it a normal behavior that INTERFACE PAIR VIEW becomes grayed? I found this VIEW helpful sometimes.

[ul]
  • I would not say that that is a best practice, no.  In my opinion it is far more confusing BECAUSE it causes the behavior you are also unhappy with (you lose interface pair view).
  • In the other FortiGate you have probably enabled Multiple Interface Policies under System -> Feature Visibility See also: https://kb.fortinet.com/kb/documentLink.do?externalID=FD46771 
  • Yes, this is a direct consequence of using multiple interfaces (or any) as a source or destination in a single policy.  What you save in multiple policies you lose in ease of looking at interface pairs.  I guess it depends on your use case, but I am currently happier to duplicate policies than to lose interface pair view.[/ul]
  • fat
    fatAuthor
    Visitor III
    November 6, 2020

    Hi Lobstercreed,

     

    Thank you very much for your clear explaination.

    I'm agree with you to keep the "interface pair view" for more visibility of policy.

     

    Best Regards.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!