Created on 08-01-2024 11:26 PM Edited on 12-30-2024 02:21 AM By Jean-Philippe_P
Description | This article describes the case when a VIP Object is not appearing in Destination while creating a Firewall Policy. |
Scope | FortiGate. |
Solution |
While creating a Firewall Policy in the destination field VIP is not visible even though it is configured.
This is because the VIP might be associated with a particular interface, and it will be visible only for the policy having the source interface the same as the associated interface. Verify the associated interface in VIP on GUI.
In the below example VIP is associated with port5 hence the VIP will be only visible in the policy having source interface as port5.
To add the VIP in other policies, change the interface of VIP to any and post that it will be visible.
Same can be verified through the CLI.
config firewall vip
To change the interface binding run the below commands.
config firewall vip end
Note: To change the interface to ANY make sure that there is no reference to the VIP. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.