Description |
This article describes the functionality of interface-policy on FortiGate. |
Scope | FortiGate. |
Solution |
Consider an interface-policy configured on FortiGate as follows:
config firewall interface-policy
As per the IPS log entries, traffic is showing 'srcip="10.20.0.70" and dstip="192.168.10.10"' which contradicts the destination address object "VLAN20_Subnet" defined in interface-policy ID 1:
date="2025-05-10" time="14:20:34" type="utm" subtype="ips" level="alert" action="detected" sessionid=1560004123 srcip="10.20.0.70" dstip="192.168.10.10" srcport=48026 dstport=22 attackid=51006 severity="critical" proto=6 logid="0419016384" service="SSH" policyid=1 incidentserialno=35747872 crscore=50 craction=4096 crlevel="critical" direction="outgoing" profile=" all_default " srcintf="VLAN30" dstintf="VLAN10" ref="http://www.fortinet.com/ids/VID51006" attack="Apache.Log4j.Error.Log.Remote.Code.Execution" eventtype="signature" srccountry="Reserved" msg="apache: Apache.Log4j.Error.Log.Remote.Code.Execution" tz="+0100" dstcountry="Reserved" poluuid="b7c08d6c-1491-51f0-a0a2-0ec15c9290c1" devid="FGxxxxxxxxx" vd="root" devname="FGT_VM" cve=CVE-2021-4104,CVE-2021-44228,CVE-2021-45046
The traffic matching interface-policy applies to both directions (incoming and outgoing). In the IPS log entry shown above, the traffic is hitting the interface-policy in the reply direction.
diagnose firewall iprope list | grep -B 4 -A 9 group=0005000
policy index=1 uuid_idx=0 action=accept
The interface-policy does not work as a normal firewall policy. In a normal firewall policy, traffic is matched based on the source/destination address, and a session gets created. If the traffic is initiated from the destination address, the traffic does not match the intended firewall policy.
In the case of interface-policy, traffic is matched in both directions (incoming and outgoing). When traffic is initiated from 10.20.0.0/24 subnet ('VLAN20_Subnet'), the interface policy gets matched. The usage of srcaddr and dstaddr in interface-policy is not as per se or used like a firewall policy.
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.