Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor III

Problems creating a NEW SASA Interface with ALL Internet Access

Hi,

 

I dont know what to do, I have problems creating a SASE Interface with the Internet Access lines I would like to use for the balancing. This comes all from older configuration and we added other lines after some time.

 

Right now I have in SD WAN the following entries:

Virtual-wan-link
> WAN1
> WAN3

upg-zone-port9
> WAN Port 9

SASE
> WAN2
> WAN4

 

I am not able to delete or get the WAN Port 9 into the SASE. I dont know how to do that and I dont find information. I think if I add WAN 9 in the SASE I could use SASE in the outgoing Interface for WWW Policies. The problem is that in Policies I cant change to Interface Pair View because I have in some polcies SASE + upg-zone 9 as outgoing interface and I need this one also.

 

Any suggestions?

 

Thanks!

2 REPLIES 2
lcucchetti
Staff
Staff

to add an Interface to an SD-WAN zone you MUST be sure that the interface itself is used nowhere, remove any reference to the interface (FW Policy, Routing and so on).. once all references will be removed you will be able to add it to the SD-WAN zone

RolandBaumgaertner72

Hi,

 

thanks for the response.

 

Thats what I am usually doing and sofar I didnt have the problem to delete references in routing, vips, policies (i just change to other interfaces like DMZ), BUT in this case I cant get it out of the upg-zone-port9. No change to delete it from there.

 

Any idea?

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors