Hi ,
I have few firewalls - virtual machines running v7.4.8 all the virtual firewalls are configured with SD WAN rules. This is a SD-WAN setup - Hub & spoke topology.
My requirement is DSCP values configured on a Fortigate firewall should be left untouched on other Fortigate firewall.
My setup is a hub and spoke setup.
Can anyone please give practical example of configuring DSCP values on a firewall from Forti manager GUI or FortiGate firewall CLI so that same DSCP values are reflecting on other firewall
hi,
based on my understanding of the article, DSCP is per policy enabled for traffic.
https://docs.fortinet.com/document/fortigate/7.4.8/administration-guide/813032
this would mean that you would need to set it for traffic on all firewalls, otherwise if not enabled/configured it will be CS0/default when traffic reaches the local FGT.
for FMG, https://docs.fortinet.com/document/fortimanager/7.4.8/administration-guide/812215
they should be there, as per https://docs.fortinet.com/document/fortigate/7.4.8/cli-reference/333889629/config-firewall-policy
Hi my setup is a virtual machine - fortigate VM-64 v7.4.8
Hence i'm unable to setup diffserv commands.
Are diffserv commands only meant to work on hardware appliances ?
If yes can you please give me the equivalent of setting up dscp on Virtual machines
Thanks ,
Prabhu
i am unaware of such a limitation.
on a FG-VM that i have access to, i can see the options even tho disabled in the cli
config firewall policy
edit <>
show full | grep diff
set diffserv-copy disable
set diffserv-forward disable
set diffserv-reverse disable
| User | Count |
|---|---|
| 2822 | |
| 1431 | |
| 812 | |
| 785 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.