Created on
09-23-2024
09:31 PM
Edited on
03-03-2025
12:17 AM
By
Jean-Philippe_P
Description |
This article describes some situations, where it needs to configure negate feature to restrict accessing or restrict the packets like srcaddr-negate, dstaddr-negate, or service-negate under the local-in-policy setting in the FortiGate unit. |
Scope | FortiGate. |
Solution |
When configuring 'negate' features under local-in-policy settings like srcaddr-negate, dstaddr-negate, or service-negate, it shows the error message as below.
FGT # config firewall local-in-policy FGT (local-in-policy) # edit 1 FGT (1) # set srcaddr-negate enable command parse error before 'srcaddr-negate' FGT (1) #
To fix that, it is necessary to upgrade the firmware version of the FortiGate unit to v7.0.x and above.
FGT # config firewall local-in-policy
Note: Starting from v7.6.0, the Local-in-Policy can now be also configured in the GUI. Refer to this article: Technical Tip: Creating a Local-In policy (IPv4 and IPv6) on GUI.
In the GUI, there is a direct button for the negate feature on the local-in-policy:
Related articles: Technical Tip: Firewall Policy 'Negate' option Technical Tip: SSL VPN tunnel mode: negating split tunneling Routing Address IPs |