Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I think it' s also important to note that when you create and address object and select " any" in the interface this doesn' t mean that your policy is necessarily using the " any" interface. (...)Yes, all you' ve written is perfectly clear to me.
Some of the above discussion is also centered around creating policies using Source Interface: Any Destination Interface: Any This is different from what I believe your initial question was about.Actually, this is exactly what my initial question was about. Yes, we drifted away a bit along the way, but the main issue for me here is to determine if there are any security drawbacks stemming from the use of the any interface in policies. Your answer was that there are none, but then ede_pfau suggested it might cause undesired traffic to be passed through the firewall. So far the picture I get is that using the any interface only increases the chance of human error while defining policies, but otherwise, if the policies are defined correctly, using specific interfaces/zones in policies does not increase the security of the setup because RPF is still in place. The only way I can be convinced that any is evil ;) would be to present me with a specific example of how can a firewall configured with policies using any be tricked into allowing traffic that wouldn' t be allowed by a corresponding configuration using specific source/destination interfaces/zones in its policies.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.