Description | This article describes the items that must be verified when a VDOM in FortiGate is converted from policy-based to profile-based. |
Scope | FortiGate, VDOM, Profile-based. |
Solution |
When a VDOM is changed from policy-based to profile-based base there can be situations where certain issues might occur, especially with loopback interfaces.
In such instances, consider the following configurations and make sure they are correctly configured.
Ensure the loopback interface still has the correct IP address and is enabled.
In profile-based mode, it is required to configure explicit firewall policies for traffic to reach the loopback interface.
Ensure there is a route back to the source IPs trying to access the loopback.
If the public IP is NATed to the loopback, ensure the VIP (Virtual IP) or DNAT rules are still in place and correctly mapped.
In profile-based mode, security profiles (like IPS, AV, etc.) can block traffic if misconfigured.
Check if any local-in policies are blocking access to the loopback.
If NAT is enabled in the policy, ensure it’s not overriding the destination IP or causing asymmetric routing. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.