Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Toshi_Esumi
SuperUser
SuperUser

Policy order: any int to any int or specific interface pair

Please let me make sure the order a FGT examine policies.
If there is a specific policy from a specific interface like "lan" to another specific interface like "wan1" with "any" source and "any" destination, it would be examined before another policy from "any" interface for a specific source IP set to "any" interface for "any" destination, even if the source IP matches one of those specified. Right?

I just want to make sure my basic/fundamental understanding is correct.

Toshi

1 Solution
Toshi_Esumi
SuperUser
SuperUser

I found the answer myself by moving the deny policy at the top in the sequence. It's now blocking.
So if "any" int->"any" int "deny" policy comes first before the specific interface pair allow policy, it would match the deny policy first.

Toshi

View solution in original post

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

Or, unless the "any" int->"any" int "deny" policy is "placed in the sequence" before the specific int pair policy?

Toshi_Esumi
SuperUser
SuperUser

I found the answer myself by moving the deny policy at the top in the sequence. It's now blocking.
So if "any" int->"any" int "deny" policy comes first before the specific interface pair allow policy, it would match the deny policy first.

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors