As suggested by my contacts within Fortinet, I'm posting this on the
community page as well. In a network that is fully leveraging BGP for
any routing decisions by matching (extended) community strings, it would
be nice if the community string was ab...
I see no reason why you wouldn't be able to use the same method to
control traffic from WAN as well, either using the same community string
or using an additional one. It might need a bit more thought if you are
employing NAT with Virtual IP objects ...