Hi, Interface1 interface2
I have created the policy source is interface 1 and destination is interface 2
Why do I have to create a policy in reverse direction ( I mean source is interface 2 and destination is interface 1)
Thanks
Solved! Go to Solution.
sims wrote:
Why do I have to create a policy in reverse direction ( I mean source is interface 2 and destination is interface 1)
Umm, you don't, unless you have sessions starting from interface 2
Too little info here to help
Of course not, as James said. Unless the server A in VLAN 101 initiates connections to client A in VLAN 100, no policy in the reverse direction would be needed. That's one of the most basic things that should be understood about stateful firewalls.
If you're defining stateless ACLs (like on a Cisco switch or something) then you need all that reverse stuff, but the whole point of firewalls is that they are far superior to that.
sims wrote:
Why do I have to create a policy in reverse direction ( I mean source is interface 2 and destination is interface 1)
Umm, you don't, unless you have sessions starting from interface 2
Too little info here to help
Hi,
Sorry for the confusion .
My question was this client A from VLAN100 is accessing 443 on server A which is in VLAN 101,
in that case do I need reverse policy from VLAN 101 to VLAN 100
sorry for my english
Thanks
Of course not, as James said. Unless the server A in VLAN 101 initiates connections to client A in VLAN 100, no policy in the reverse direction would be needed. That's one of the most basic things that should be understood about stateful firewalls.
If you're defining stateless ACLs (like on a Cisco switch or something) then you need all that reverse stuff, but the whole point of firewalls is that they are far superior to that.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.