| Description | This article describes the Firewall Policy change based on policy view when multiple interface policy is enabled and are in use. |
| Scope | FortiOS. |
| Solution | When a firewall policy makes references to more than one interface in either 'Incoming interface' or 'Outgoing interface' (This requires 'Multiple Interface Policies' to be enabled under System -> Feature) the behavior exhibited by the GUI firewall policy table (Policy & Objects -> Firewall Policy) will differ based on if the policy view is 'By Sequence' or 'Interface Pair View'. The behavior is explained in the demonstration below.
When the Policy view is changed to Interface pair view, the single policy (test4) will be displayed as two separate policies:
In the visual demonstration below, when a change is made on one of the two policies, it will be reflected on both policies when the interface pair view is selected.
This is an expected behavior in how the GUI displays the interface-pair view when multiple interfaces are selected in the firewall policy. While two entries are shown in the GUI (to display proper interface pairs), modifying either will modify the single policy that is present in the configuration, which is then reflected to 'both' policies in the GUI.
edit 21 set name "test4" next end
If there is a need to treat traffic differently coming from one interface than another, then it is necessary to split up this policy into two separate policies for each interface pair. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.