Description | This article describes how local out traffic is handled when policy-based IPsec is configured. |
Scope | FortiGate. |
Solution |
In FortiOS documentations, it is possible to find that self-originating traffic from the firewall (such as license validation, FortiGuardconnections etc..) is normally not checked against regular Firewall policies.
Note: Because of this, extra care should be taken when configuring policies for policy-based IPsec. Avoid using destination 'all' in the destination address and destination interface fields, or if necessary, consider the possibility that the traffic might match an IPsec policy and get dropped by phase2 selectors mismatch. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.