Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rob8435
New Contributor

Virtual IP - "extintf"

Hello,

please, can somebody explain me extintf attribute in config firewall vip?

I set new dNAT a is seems it doesn't matter what interface is selected in "extintf" parametr (it works also with disabled/not connected device selected in "extintf").

 

FortiOS 6.4.6.

 

Thank you.

Rob

1 REPLY 1
localhost
Contributor III

As far as I know, it only has an impact on hairpain NAT rules.

If you don't match it to the correct interface or set the value to 'any', you'd have to create a seperate policy for each source-destination combination.

 

See the DMZ example in following knowledge base article:

https://kb.fortinet.com/kb/documentLink.do?externalID=FD36202

 

Top Kudoed Authors