Hi,
"For the public Cloud VMs, the status of 'allow-traffic-redirect' is always set to disable due to one-arm traffic." is advised in this KB: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Traffic-handled-by-FortiGate-for-packet-wh...
However, looking at my existing configuration for 7.0.12, "allow-traffic-redirect" is currently enabled.
Tried to look at a newly provision VM which is at 7.2.9, "allow-traffic-redirect" is currently disabled.
Would you know at which FortiOS version was the default value changed?
My existing configuration was from 6.0
Thanks!
Are you deploying the new VM from a cloud image? You would see the provider (e.g. AWS, Azure, GCP) in the name of the VM image if this is the case. The 'allow-traffic-redirect enable' would not be the default for regular VM images.
It is forced to "disable" by default since 6.4.3/7.0.0 in new deployments. (not listed in release notes, don't waste your time looking for it like I did. :) )
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.