| Description | This article describes how, starting from v7.6.x, a Local-In policy can be created via the GUI. |
| Scope | FortiGate v7.6.x. |
| Solution |
Starting from FortiOS v7.6.0, Local-In policies can be created on the GUI. In previous firmware versions, this option was only available via the CLI. See Local-in policy.
configure system settings set gui-local-in-policy enable
config firewall {local-in policy | local-in-policy6} edit <policy number> set int <interface> set srcaddr <source address> set dstaddr <destination address> set action {accept | deny} set service <service name> set schedule <schedule name> set virtual-patch {enable| disable} set comments <string> next end
In the GUI:
The Negate option can also be used for source and destination addresses in both local-in policies and firewall policies by enabling Policy Advanced Options under System -> Feature Visibility. (For more details, see Technical Tip: Firewall Policy 'Negate' option.)
As best practices, consider the following recommendations:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.