Created on
10-18-2023
09:42 PM
Edited on
06-24-2025
12:37 AM
By
Jean-Philippe_P
Description | This article describes how to allow or block intra-traffic in the zone. |
Scope | FortiGate. |
Solution |
It is possible to allow or block intra-zone traffic by enabling or disabling the 'Block intra-zone traffic' option.
It is also possible to enable or disable from the CLI:
config system zone
To control further, it is possible to 'set intrazone allow' for the zone and then add firewall policies to block some traffic. For example, it is possible to block traffic from one direction port1 -> port4, and allow the opposite direction from port4 to port1 inside the zone.
Steps to allow or deny traffic between subnets in the same zone:
Two policies are required to control traffic between subnets:
During troubleshooting, 'debug flow' will not show any messages, it is possible to track the connection only using 'diagnose sniffer' and filter by session list. Example of session list for a session between 2 hosts in the same zone when 'set Interzone allow' is configured (hosts are located behind 2 different interfaces but in the same zone) :
Policy 4294967295 refers to a local-in policy, which takes precedence over other firewall policies because intra-zone traffic is allowed by default. Traffic allowed by this feature is not logged in the forward traffic logs.
session info: proto=6 proto_state=01 duration=27 expire=3591 timeout=3600 flags=00000000 socktype=0 sockport=0 av_idx=0 use=3
Note: Intrazone traffic with one member part of the zone.
If the zone has one member only, to control Intrazone traffic:
However, when having one member only and Intrazone 'allow' is set (condition 2.a.), an accept policy is not created for the zone. Therefore, Intrazone traffic is blocked under that condition.
This behavior is fixed starting from FortiOS v7.4.4. Starting from that version and on, an accept policy is created when one interface is part of the zone, and the Intrazone traffic is allowed.
Related article: Technical Tip: How to enable local intra-zone traffic logs |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.