Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
smxko
New Contributor III

SD WAN on VIP article 408308

Hello,

 

please help me understand this article. I have a WAN interface in a SDWAN zone which is used for DNAT. And occasionally the policy that contains the VIP won't get hit and traffic doesn't pass. Now there's this article explaining how to handle VIPs when the interface is a SDWAN member.

Creation of a VIP (DNAT) when WANs are in... - Fortinet Community

 

The article basically states:

- On the VIP, use the physical interface, not the zone

- On the policy, use the physical interface as incoming interface, not the zone

 

Now the catch is,  you can't even use zones in the VIP interface selection GUI. And furthermore, you can NOT select the physical interface in a security policy when it is part of a zone.

What is this tip even about? The first one is useless because that's a restriction of FortiOS and the second one is also not applicable because it's just not possible. If "wan" is part of "virtual-wan-link" you can only ever reference that zone in a policy, never the interface itself unless it is released from that zone.

 

Or has this behavior changed in newer versions?

1 Solution
AEK
SuperUser
SuperUser

Hi

Old FortiOS may differ from the new.

The currently correct is: Use physical interface in VIP and use SD-WAN interface in firewall policy.

AEK

View solution in original post

AEK
1 REPLY 1
AEK
SuperUser
SuperUser

Hi

Old FortiOS may differ from the new.

The currently correct is: Use physical interface in VIP and use SD-WAN interface in firewall policy.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors