Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
solidblueliquid
New Contributor

Can you set a physical port to bypass the firewall rules?

I want to set one of my physical ports to bypass the security of the firewall. I currently sell the firewall as additional feature, so to accommodate this i'll like to set a port (say 14 for argument sake) to just allow all traffic in and out but still be monitored by the firewall.

 

Is that possible?

3 REPLIES 3
emnoc
Esteemed Contributor III

You could apply a firewall policy with any/any  for  both  directions. This is not "TECHNICALLY" bypassing a firewall and no you can't BYPASS a port .

 

 A firewall is a firewall , and if your really  have tiers you should not place the  traffic thru a firewall/ The reason why, the  ANY/ANY approach mention above  eat resources  of a firewall and sessions.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
solidblueliquid

I figured that'll be the answer, so better i just have a cable to a switch that's directly connected to the outside world?

ede_pfau

No. Even if the policy allows ANY service to ANY destination, anytime, the firewall still provides routing and SNAT, and some protection if you apply UTM (AV, IPS). The latter might have an impact on the traffic - your call, this depends on your goal.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors