Hello,
I have configured a VIP with interface "any" and added optional filters, having source IP address specified. The translations occures all the time, even if the traffic is not coming from the specified source. I'm running FortiOS 5.6.3. In my view this is not a correct behavior. Does anybody else have the same issue?
Thank you guys already for your support.
CHgeek
Hi,
It is actually normal behaviour because by default, firewall policies will not match VIP if the latter is not enabled on them. As such, on the CLI, do the following:
config firewall policy
edit [policy that VIP has been configured as the destination on]
set match-vip enable
end
I hope that helps.
NSE5, CCSE, CCNA R&S, CompTIA A+, CompTIA Network+, CompTIA Security+, MTA Security, ITIL v3
Yes, I have same problem with 7.0. Have you found solution? Interface "any" is necessary for me because I want to use it for multiple interfaces.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1112 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.