Skip to main content
smxko
Visitor III
November 17, 2025
Solved

SD WAN on VIP article 408308

  • November 17, 2025
  • 1 reply
  • 446 views

Hello,

 

please help me understand this article. I have a WAN interface in a SDWAN zone which is used for DNAT. And occasionally the policy that contains the VIP won't get hit and traffic doesn't pass. Now there's this article explaining how to handle VIPs when the interface is a SDWAN member.

Creation of a VIP (DNAT) when WANs are in... - Fortinet Community

 

The article basically states:

- On the VIP, use the physical interface, not the zone

- On the policy, use the physical interface as incoming interface, not the zone

 

Now the catch is,  you can't even use zones in the VIP interface selection GUI. And furthermore, you can NOT select the physical interface in a security policy when it is part of a zone.

What is this tip even about? The first one is useless because that's a restriction of FortiOS and the second one is also not applicable because it's just not possible. If "wan" is part of "virtual-wan-link" you can only ever reference that zone in a policy, never the interface itself unless it is released from that zone.

 

Or has this behavior changed in newer versions?

Best answer by AEK

Hi

Old FortiOS may differ from the new.

The currently correct is: Use physical interface in VIP and use SD-WAN interface in firewall policy.

1 reply

AEK
SuperUser
AEKAnswer
SuperUser
November 17, 2025

Hi

Old FortiOS may differ from the new.

The currently correct is: Use physical interface in VIP and use SD-WAN interface in firewall policy.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!