Skip to main content
sw2090
SuperUser
SuperUser
June 11, 2019
Question

Group Interfaces in Policy to not lose interface pair view?

  • June 11, 2019
  • 1 reply
  • 2531 views

I need a policy that allows traffic from a load of subnets coming in via a load of ipsec tunnels to access one server with one service. I can build an address group that contains all those subnets and use it in the policy but how about the source interface?

If I set this to "any" the policy will work but I lose the interface pair view in gui which is a bad thing if you have over 1,5k of policies. Is there any way to create a "group" of interfaces to set that as source in the policy in order not to lose pair view?

Also that would enable me to reduce the number of policies on this Fortigate a load :)

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    June 11, 2019
    We always bind IPSec vpns to a zone even when only one vpn exists. With this way policies look or exactly the same all installations.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!