Skip to main content
Charlez79
Visitor III
April 15, 2022
Question

unable to select "sd-wan" as Outgoing Interface in ipv6 policy

  • April 15, 2022
  • 4 replies
  • 2206 views

Hi,

 

When setting up a new ipv6 policy, i'm unable to select  "sd-wan" as outgoing interface, getting error "Failed to save some changes: Input value is invalid."

What could be the cause of this?

No other ipv6 policies are configured

Only "Any" as Outgoing Interface is accepted.

 

for ipv4 policies can be configured with sd-wan as outgoing interface.

 

running FGT-90D v6.0.14

SD-WAN ipv6 should be available as of 6.0

 

Anyone who can point me to the right direction where to look at?

 

thx

4 replies

Charlez79
Charlez79Author
Visitor III
April 16, 2022

Found the cause, kernel to old.

hoisn
New Member
August 11, 2024

May I know the solution to your problem? I have the same problem..

rishab444
Staff
Staff
August 11, 2024

Hello @Charlez79 and @hoisn ,
I have confirmed this is working with 6.0.14, 6.0.18, 7.2.8 and 7.4.4. Could be just a glitch on your end.
Galileo-kvm52 # get sys status
Version: FortiGate-VM64-KVM v6.0.14,build0457,211118 (GA)
Virus-DB: 1.00000(2018-04-09 18:07)
Extended DB: 1.00000(2018-04-09 18:07)
Extreme DB: 1.00000(2018-04-09 18:07)
IPS-DB: 6.00741(2015-12-01 02:30)
IPS-ETDB: 0.00000(2001-01-01 00:00)
APP-DB: 6.00741(2015-12-01 02:30)
INDUSTRIAL-DB: 6.00741(2015-12-01 02:30)
Serial-Number:
IPS Malicious URL Database: 5.00139(2024-08-11 07:30)
Botnet DB: 4.00888(2024-08-01 22:01)
License Status: Valid
VM Resources:
BIOS version: 04000002
Log hard disk: Available
Hostname: Galileo-kvm52
Operation Mode: NAT
Current virtual domain: root
Max number of virtual domains: 10
Virtual domains status: 1 in NAT mode, 0 in TP mode
Virtual domain configuration: disable
FIPS-CC mode: disable
Current HA mode: standalone
Branch point: 0457
Release Version Information: GA
FortiOS x86-64: Yes
System time: Sun Aug 11 17:15:26 2024

Galileo-kvm52 # conf firewall policy6

Galileo-kvm52 (policy6) # sh
config firewall policy6
edit 1
set name "Test"
set uuid 1d39aa38-5814-51ef-84ae-1e0c615d017b
set srcintf "port1"
set dstintf "virtual-wan-link"
set srcaddr "all"
set dstaddr "all"
set action accept
set schedule "always"
set service "ALL"
set nat enable
next
end


 

Regards,
Rishab

hoisn
New Member
August 12, 2024

not sure what glitch is, my results using the cli is:

 

FGT60D (policy6) # edit 4
FGT60D (4) # set dstintf "virtual-wan-link"

 

node_check_object fail! for name virtual-wan-link
value parse error before 'virtual-wan-link'
Command fail. Return code -651

 

Using v6.0.18

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!