FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jclar
Staff
Staff
Article Id 323208
Description This article describes how to add an existing and used interface in a zone.
Scope FortiGate, SD-WAN.
Solution

By default, adding an interface in a zone should only be a couple of clicks away. However, some wish to add an existing and used interface in a newly created (or possibly existing) zone.

 

Below is a demonstration of how to add a new interface to the zone.

 

Port4 is a new interface with no references:

 

Port4_NoReference.png

 

Under Network -> SD-WAN, select Create New -> SD-WAN Member -> OK.

 

Create_Port4.png

 

The interface is already added on the virtual-wan link zone.

 

Port4_Zone.png

 

In this case, an admin wanted to add the existing WAN interface, which is port1. Note that this interface was already used as this was the only WAN that the admin initially had.

 

  • Port1 does not show in the 'Interface' drop-down menu for an SD-WAN member:

Port1_NoShow.png

 

This is because port1 has references which may include policy config, VPN config, VIP config and etc.

 

To resolve this, all references should be deleted or moved to a different interface until the number of references becomes 0, and the port can be added on the zone interface.

 Port1_withRef.png

 

Deleted references:

 

Port1_NoRef.png

 

A new SD-WAN member was created, and port1 is now visible on the drop-down list:

 

Port1_SDwan.png

 

Contributors