- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Source Interface Selection
Hi
I have port1 (LAN) and created 10 sub-interfaces for Vlans. So in Source interface selection box on all fortigate configuration, should I select Port1 or should I select Vlan interfaces?
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey rezafathi,
you have multiple options:
- you can add all 10 vlans to a zone (but then you can only use the zone interface for policies)
- you can create 10 policies, one for each VLAN
- you can enable 'Multiple Interface Policy' under System > Feature Select to allow adding more than one source interface in a policy
-> please note that this will disable the interface-based view in GUI! Policies will no longer be sorted by source/destination interface, but instead by their configured order only.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear Rezafathi,
when you create VLAN interface on the firewall, VLAN interfaces will be becoming your logical interfaces for policy inspection, so in the source interface section of firewall policy, you will need to select the VLAN interfaces in order to control the traffic(received on the VLAN interface) based on firewall policy.
Hope this helps!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks. in firewall policy I can only select one incoming interface but multiple sources. So if i want to give 10 vlans internet access what should I do?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey rezafathi,
you have multiple options:
- you can add all 10 vlans to a zone (but then you can only use the zone interface for policies)
- you can create 10 policies, one for each VLAN
- you can enable 'Multiple Interface Policy' under System > Feature Select to allow adding more than one source interface in a policy
-> please note that this will disable the interface-based view in GUI! Policies will no longer be sorted by source/destination interface, but instead by their configured order only.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks. I think the last option is reliable. is that right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @rezafathi
The respective would also depends on the services that you permit in the firewall policy. It will ease your management if all of the VLANs have the same privilege and access to the Internet. It also make your firewall policy cleaner (1 vs 10). The only draw back is that you can only view your firewall policy in sequence view.
Kayzie Cheng
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @rezafathi,
It depends where traffic comes from. You can use sniffer to see incoming interface and use it as source interface. To sniff traffic, use this command " diag sniffer packet any "host X.X.X.X" 4 0 l ".
Regards,
Minh
