FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jbernabe
Staff
Staff
Article Id 351655
Description This article describes that it is possible to get an error notification when selecting the VPN tunnel as an Incoming/Outgoing interface in the Firewall Policy.
Scope FortiGate.
Solution

The error notification image below is received when selecting the VPN tunnel as an Incoming/Outgoing interface in the Firewall Policy.


invalid2.JPG
The error notification will appear if the selected VPN tunnel interface is a member of a Zone. To resolve this find the Zone where the VPN tunnel is member.

In this image example below VPN tunnel interface 'S2S' was a member of a Zone 'vpn_S2S_zone'. Zone can be found on the FortiGate GUI under Network -> Interfaces -> Zone.


invalid3.JPG

 

Once the Zone is identified, Select the identified Zone as an Incoming/Outgoing Interface on the Firewall Policy.

 

invalid4.JPG

 

The error notification message will disappear as the correct Zone is applied where the VPN tunnel interface is a member.

 

Contributors