Hello,
We have couple FGT-300D devices running FortiOS v5.2.6,build711 GA and we are migrating configuration and policies to zone from interfaces (physical and VLANs). But I an unable to add loopback interfaces to a zone. Loopback if is not referenced in any policies, but still not available to be added to a specific zone. Tried from GUI and CLI.
Does this OS have a bug regarding this issues or this is a product design restriction?
Thank you!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I believe this is a limitation in FortiOS & multi-Vdom and nonMulti-Vdom models running 5.2.x don't allow for loopback type interfaces to be in a zone definition.
You can open a case with FTNT support and see what they say.
ken
PCNSE
NSE
StrongSwan
Technically, a zone isn't an interface, it's a group of interfaces treated equally... Think of it like an address vs an address group in concept, not operation.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Yeah, but you still can't install a "loopback" interface into a zone.
I'm only aware of the following supported interfaces for a zone concept;
[ul]
I believe something has changed over the course of the last major release iirc loopback could be in a zone in the pass. Some correct me if this is not correct? I don't have anytihing in pre 5.0.x to test so I can't prove that theory.
edit: add vdom-interlink to supported interfaces types also for the "zone"
Ken
PCNSE
NSE
StrongSwan
Correct me if I'm wrong. A loopback interface belongs to a device. It is always up and should be reachable by any means allowed by that device's ACL. I just set up a test loopback on my 4.3.17 FGT. There was no provision to apply it to any interface or zone. is that a CLI only option or something?
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Yes that's a interface that's virtual. I don't think you can craft ( webgui ) but only from the CLI. We used loopback for SSLVPN portal terminates and sources for logging, ospf,etc....
IIRC maybe in fortiOS v3.x you could apply a loopback into a zone , but my memory is fogging. In current v5.x you CAN NOT. I think that's what the OP was finding also.
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.