FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rishab444
Staff
Staff
Article Id 270527
Description This article describes the scenario when getting the node_check_object fail error while setting up the interface under local-in-policy.
Scope

FortiGate. v7.4.6+

Solution
  1. When the interface is set under local-in-policy, the error 'node_check_object fail! for intf portX' is faced.

 

rishab444_0-1692988514652.png

 

  1. Or when trying to create a firewall policy with the wan interface of the SD-WAN member does not show up:                                                                             Capture-232.PNG

     

  2. This is an expected behavior in v7.4.6 and above when the interface is part of a Zone under interfaces as seen below:

 

rishab444_1-1692988514659.png

 

  1. To overcome and proceed to create the local-in-policy, it is necessary to refer to the Zone itself in the Local-in-policy as seen below:

 

rishab444_2-1692988514663.png

 

This is useful, especially in environments with multiple WANs that are put together in a WAN-Zone/Untrust-Zone.