Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rhap4boy
New Contributor

Not possible to specify individual interface after adding interface to a zone?

Is it correct that after you add an interface to a zone, you will not be able to add the interface individually as source or destination interface to a firewall policy?  You can only add the zone.  Is there a workaround?

1 REPLY 1
lobstercreed
Valued Contributor

That is the whole point of zones, so no, there's not a workaround. 

 

You can still effectively control traffic between interfaces in a zone if you have the zone set not to allow intrazone traffic and then you create a policy with both the source and destination interfaces set as the zone.  Then you control traffic by specifying source/destination addresses correctly.

Labels
Top Kudoed Authors