Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

incoming and outgoing traffic on same IF ?

hi, somebody know if it is possible to create rule where incoming and outgoing interface is the same ? thanks, gnjb
3 REPLIES 3
UkWizard
New Contributor

I dont think this is possible. Even if it was, you wouldnt be able to apply rules to it anyway. Why would yoy want to do this ?, you could do a fudge possibly with two interfaces on the same network though ? bit dodgy that though. Explain your scenerio, maybe we can suggest an alternative method.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

ok here is it: we have a vpn concentrator in the dmz. approx. 100 branch offices are connected/terminated at this concentrator. if one branch office talks to another branch office the traffic is not visible to the firewall becuse the concentrator routes the traffic just through the tunnel to its destination. we will get a new vpn provider soon, and for them it is possible to route all traffic first to the firewall and then back to the concentrator (by mpls i think). this is the problem: we like to restrict this traffic on the firewall but incoming and outgoing interfaces are the same ... any ideas ? thanks gnjb
Not applicable

you could do a fudge possibly with two interfaces on the same network though ?
imho not a good solution. you will always get in trouble with asymmetric routing. (packet enters one interface, and the reply to that " flow" leaves another interface). ?!?? gnjb
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors