| Description |
This article describes how the firewall policy can take effect when FortiGate is in One-Arm mode in a different firmware version. |
| Scope | FortiGate v6.4.X, v7.0.X, v7.2.X, v7.4.X. |
| Solution |
In the following diagram, PC1 is trying to ping PC2. Both PCs are using the FortiGate as their gateway. FortiGate Port3 has a primary IP address and a secondary IP address.
config firewall policy
config system interface edit port3 set icmp-send-redirect disable end
Related article: Technical Tip: Traffic handled by FortiGate for packets with ingress & egress as same interface |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.