Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
catalin_plotogea
New Contributor

FortiGate unable to add loopback interface to zone

Hello,

 

We have couple FGT-300D devices running FortiOS v5.2.6,build711 GA and we are migrating configuration and policies to zone from interfaces (physical and VLANs).  But I an unable to add loopback interfaces to a zone. Loopback if is not referenced in any policies, but still not available to be added to a specific zone. Tried from GUI and CLI.

 

Does this OS have a bug regarding this issues or this is a product design restriction?

 

Thank you!

5 REPLIES 5
emnoc
Esteemed Contributor III

I believe this is a limitation in  FortiOS &  multi-Vdom and nonMulti-Vdom  models running 5.2.x don't allow for loopback type interfaces to be in a zone definition.

 

You can open a case with FTNT support and see what they say.

 

ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
rwpatterson
Valued Contributor III

Technically, a zone isn't an interface, it's a group of interfaces treated equally... Think of it like an address vs an address group in concept, not operation.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
emnoc
Esteemed Contributor III

Yeah, but you still can't install a "loopback" interface into a zone.

 

I'm only aware of the following supported interfaces for a zone concept;

 

[ul]
  • tagged-802.1q
  • tunnel( gre/ipip/ipv6 )
  • vpn-tunnel
  • physical
  • aggregate[/ul]

     

    I believe something has changed over the course of the last major release iirc loopback could be in a zone in  the pass. Some correct me if this is not correct?  I don't have anytihing in  pre 5.0.x to test so I can't prove that theory.

     

    edit: add vdom-interlink to supported interfaces types also for the "zone"

     

     

    Ken

     

     

  • PCNSE 

    NSE 

    StrongSwan  

    PCNSE NSE StrongSwan
    rwpatterson
    Valued Contributor III

    Correct me if I'm wrong. A loopback interface belongs to a device. It is always up and should be reachable by any means allowed by that device's ACL. I just set up a test loopback on my 4.3.17 FGT. There was no provision to apply it to any interface or zone. is that a CLI only option or something?

    Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
    emnoc
    Esteemed Contributor III

    Yes that's a interface that's virtual. I don't think you  can craft ( webgui )  but only from  the  CLI. We used  loopback for SSLVPN portal terminates and sources for logging, ospf,etc....

     

    IIRC maybe in   fortiOS v3.x you could apply a loopback into a zone , but my memory is fogging. In current v5.x you CAN NOT. I think that's what the OP was finding also.

     

    PCNSE 

    NSE 

    StrongSwan  

    PCNSE NSE StrongSwan
    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors