Created on
09-23-2024
09:31 PM
Edited on
07-09-2025
02:03 PM
By
Jean-Philippe_P
Description |
This article describes some situations, where it needs to configure negate feature to restrict accessing or restrict the packets like srcaddr-negate, dstaddr-negate, or service-negate under the local-in-policy setting in the FortiGate unit. |
Scope | FortiGate. |
Solution |
When configuring 'negate' features under local-in-policy settings like srcaddr-negate, dstaddr-negate, or service-negate, it shows the error message as below.
FGT # config firewall local-in-policy FGT (local-in-policy) # edit 1 FGT (1) # set srcaddr-negate enable command parse error before 'srcaddr-negate' FGT (1) #
To fix that, it is necessary to upgrade the firmware version of the FortiGate unit to v7.0.x and above.
FGT # config firewall local-in-policy
Note: Starting from v7.6.0, the Local-in-Policy can now also be configured in the GUI. Refer to this article: Technical Tip: Creating a Local-In policy (IPv4 and IPv6) on GUI.
In the GUI, there is a direct button for the negate feature on the local-in-policy:
Related articles: Technical Tip: Firewall Policy 'Negate' option Technical Tip: SSL VPN tunnel mode: negating split tunneling Routing Address IPs |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.