I want to set one of my physical ports to bypass the security of the firewall. I currently sell the firewall as additional feature, so to accommodate this i'll like to set a port (say 14 for argument sake) to just allow all traffic in and out but still be monitored by the firewall.
Is that possible?
You could apply a firewall policy with any/any for both directions. This is not "TECHNICALLY" bypassing a firewall and no you can't BYPASS a port .
A firewall is a firewall , and if your really have tiers you should not place the traffic thru a firewall/ The reason why, the ANY/ANY approach mention above eat resources of a firewall and sessions.
PCNSE
NSE
StrongSwan
I figured that'll be the answer, so better i just have a cable to a switch that's directly connected to the outside world?
No. Even if the policy allows ANY service to ANY destination, anytime, the firewall still provides routing and SNAT, and some protection if you apply UTM (AV, IPS). The latter might have an impact on the traffic - your call, this depends on your goal.
User | Count |
---|---|
2567 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.