FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
hbac
Staff
Staff
Article Id 396349
Description

This article describes how to resolve an issue where an error message 'IP must not be zero' appears due to the 'External IP address/range' of a Virtual IP being set to 0.0.0.0. This error appears because the Interface is set to 'any' as shown below. 

 

VIP.PNG

 

From CLI:

 

Error.jpg

Scope FortiGate.
Solution

A user may use 0.0.0.0 as the External IP address/range when the WAN interface is using a dynamic IP address (DHCP). Using 0.0.0.0 can prevent issues when the WAN IP address changes. 

 

To use 0.0.0.0 as an External IP address/range, the interface must not be 'any'. Change the Interface accordingly, and the error will disappear. 

 

VIP any.PNG


This also applies to both Static NAT and FQDN types of the VIPs, where the external IP is intended to be set as any or '0.0.0.0'.

11.jpg

 

From CLI:

 

no-Error.jpg