[FortiOS 6.4.2] icmp any any
Hello,
I have some Fortigate 200E in my lab for testing.
Instead of putting several lines of policy, I use "set srcintf any" and "dstintf any" to configure the icmp policy.
As a result, only one line is enough.
In GUI, ANY didn't appear in incoming/outgoing interface, so I did it using CLI.
But after that, the "INTERFACE PAIR VIEW" was unavailable.
I'd like to know:
- is it a best practice using ANY instead of selecting a particular interface?
- ANY does appear in another Fortigate with the same firmware and model, why it didn't in this one?
- is it a normal behavior that INTERFACE PAIR VIEW becomes grayed? I found this VIEW helpful sometimes.
Thank you for your reply.
