Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Behzadawesome
New Contributor

Fortigate zone/interface level policy

Hi all,

 

Is there any functional difference between using zones in policies rather than the direct interface itself in the policies?

Using zone has the transparency layer of changing the underlying interface.

 

Regards

 Behzad

1 REPLY 1
emnoc
Esteemed Contributor III

None from a functional. If you have hundred of interfaces , a zone might be beneficial if you need to group similar policy. Just keep in mind if you ever need interface label policy and have zones you can NOT do that. BUT you can  still wrote specific policy with src/dst zone and src/dst address to that level of granular

 

FWIW I hardly use zones unless it's for VPN tunnels.

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors