FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
sreddi
Staff
Staff
Article Id 195315

Description

 

This article describes how to enable interface pair view when it is greyed out.


Solution

 

If Policies with 'any' or 'multiple interfaces' are selected in the incoming or outgoing interface, 'Interface pair view' will be disabled.

Unselect 'Any' from the policy to select 'Interface Pair View'.

 

 

There are also specific cases when the Interface Pair View it is shown as greyed out. 

One of these cases is the usage of SDWAN and zones. When different zones are created on the SD WAN and apply 2 or more of them as sources or destinations on the firewall policies, the Interface Pair View will be grayed out, as it is expected.

 

MigenaM_0-1677507900395.png

 

Below the three zones, part of the SD WAN is configured as dstintf on the Test_Policy, and as seen, the Interface Pair View it is grayed out:

 

MigenaM_2-1677508164817.png

 

In the case mentioned above, to be able to enable Interface Pair View again, the solution is to create separate firewall policies for each zone set as dstintf:

 

MigenaM_3-1677508593780.png

 

As seen, the Interface Pair View has not grayed out anymore and can be selected.