Description |
This article describes information on support for dynamic addresses to security-policy in NGFW Policy mode. |
Scope | FortiGate. |
Solution |
Starting FortiOS version 7.4.1, in FortiGate deployed in NGFW Policy mode, it is possible to use dynamic IP addresses as matching criteria in the security policies.
For example, if using the Cisco ACI external connector to fetch the tags, these tags can be called in firewall addresses (type dynamic) which would then resolve it to IP addresses.
config system sdn-connector
edit "Address_Object" Then it will be possible to call this dynamic address object in the security policy:
edit 2
Basic troubleshooting steps:
dia debug reset diag ips pme debug en
Initiate the traffic:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.