Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
James_G
Contributor III

"Block intra-zone traffic" on SD-WAN interface

On a normal zone you have the option to enable or disable "Block intra-zone traffic"

 

Whats the default behavior on an SD-WAN interface and is this configurable?

4 REPLIES 4
emnoc
Esteemed Contributor III

What do you mean normal zone & SDWAN? If you have a zones  than traffic is allowed by the policies that your create. Can you explain what intra-zone you have? and the issues ? or a topology ?

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
James_G
Contributor III

In a zone you can either allow or deny traffic between interfaces that are a member of the same zone - "set intrazone deny/allow" - this does not hit any policy and is impossible to configure a policy other then the allow / deny.

 

An example of this would be if you have an "edge networks" zone with interfaces "edge floor 1" and "edge floor 2" *not totally different to my real world*! If you set intrazone allow then network between floor 1 and floor 2 is totally open.

 

The same is true for SD-WAN interfaces, except the option to set intrazone deny/allow is not valid, I have checked with support and the default option (and only option) is to allow traffic between SD-WAN members without any policy. So for example if you have an ISP and a VPN tunnel as SD-WAN members, the Fortigate will openly route traffic between VPN to ISP and ISP to VPN without any policy checking. it's just an open router, with the only protection being NAT.

emnoc
Esteemed Contributor III

So you have a SDWAN and it's in a zone? What traffic are suspecting that is open in that SDWAN members? Can't you craft a policy that says src/dst-zone deny? BTW , never heard anyone calling up a virtaual-wan in a zone to begin with.

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
James_G
Contributor III

No zones, just using that as an example that you can configure this in a zone.

 

The real issue is that traffic between SD-WAN members is open and cannot be blocked. And it's not possible to put any policies in place as no policy processing takes place on this traffic.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors