Skip to main content
suthomas1
New Member
August 7, 2020
Solved

interface zones

  • August 7, 2020
  • 6 replies
  • 14390 views

Good day all,

 

Using zones in our fortigate firewall. Is traffic within the same source & same destination zone allowed by default or it needs a rule in place?

 

    Best answer by Toshi_Esumi

    If you want to control further, you can "set intrazone allow" for the zone then add policies to block some traffic, like blocking one direction int1->int2 while allowing the opposite direction int2->int1 inside the zone, with the same zone as its src and dst interface in the same policy. We recently needed to do that based on a customer's requirement.

    6 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    August 7, 2020

    I would assume it's blocked by default because all zones at our office has "Block intra-zone traffic" enabled, means deny. But you can easily change it via GUI or CLI (set intrazone allow).

    suthomas1
    suthomas1Author
    New Member
    August 7, 2020

    that means it traffic within same zone is not blocked by default? if you have the block intrazone traffic enable in your firewall.?

    James_G
    New Member
    August 7, 2020

    Toshi is correct about "Block intra-zone traffic" - you have option of enabled or disabled

     

    Your options are everything open, or everything blocked, you have no other granular options

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!