Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Umesh
Contributor

unable to add multiple zone incoming souce object.

Dear All,

 

Yesterday  I was configuring Fortigate Firewall and I have created multiple Zones like - APP ZONE, server zone, Prod Zone, FTP server Zone.

 

Having created above zone I was unable to add those zone incoming source address why ?.

 

At the Sophos Firewall this option is available. Can anyone explain what should I do for it, OR I am doing something wrong.

 

Your response would be highly aprriciated.

 

Thank you.

1 Solution
srajeswaran
Staff
Staff

Hi Umesh,

 

Are you saying the interface zones you created cannot be added to the source interface in policy? Are you able to add one zone atleast as source/destination interface? If you need to add multiple zones/interfaces you need to enable " Multiple Interface Policies" under "System> Feature Visibility".

You mentioned zones cannot be added as source address, not sure if it is a typo - zones can be used as Incoming or Outgoing interface and not as source/destination address.



Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

View solution in original post

3 REPLIES 3
srajeswaran
Staff
Staff

Hi Umesh,

 

Are you saying the interface zones you created cannot be added to the source interface in policy? Are you able to add one zone atleast as source/destination interface? If you need to add multiple zones/interfaces you need to enable " Multiple Interface Policies" under "System> Feature Visibility".

You mentioned zones cannot be added as source address, not sure if it is a typo - zones can be used as Incoming or Outgoing interface and not as source/destination address.



Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

Umesh

Hi suraj,

 

Thanks for your reply, I will check and get back to you.

 

Regards,

umesh

AEK
SuperUser
SuperUser

Hi Umesh

Better not using multiple interfaces, so you keep policy visibility by interface pair. It is the best view.

AEK
AEK
Labels
Top Kudoed Authors