Hello,
please help me understand this article. I have a WAN interface in a SDWAN zone which is used for DNAT. And occasionally the policy that contains the VIP won't get hit and traffic doesn't pass. Now there's this article explaining how to handle VIPs when the interface is a SDWAN member.
Creation of a VIP (DNAT) when WANs are in... - Fortinet Community
The article basically states:
- On the VIP, use the physical interface, not the zone
- On the policy, use the physical interface as incoming interface, not the zone
Now the catch is, you can't even use zones in the VIP interface selection GUI. And furthermore, you can NOT select the physical interface in a security policy when it is part of a zone.
What is this tip even about? The first one is useless because that's a restriction of FortiOS and the second one is also not applicable because it's just not possible. If "wan" is part of "virtual-wan-link" you can only ever reference that zone in a policy, never the interface itself unless it is released from that zone.
Or has this behavior changed in newer versions?
Solved! Go to Solution.
Hi
Old FortiOS may differ from the new.
The currently correct is: Use physical interface in VIP and use SD-WAN interface in firewall policy.
Hi
Old FortiOS may differ from the new.
The currently correct is: Use physical interface in VIP and use SD-WAN interface in firewall policy.
| User | Count |
|---|---|
| 2822 | |
| 1431 | |
| 812 | |
| 785 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.