Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Chaminda_K
New Contributor

Zone-mapping through Fortimanager

Hi All, In our current configuration we have a VLAN interface configured through Fortimanager to use itself as a zone-map. In the FW' s configuration an explicit zone does not exist. We are facing a situation where we need to add an additional VLAN interface into the same zone, in order to use the same rule set. However it is not possible to add another zone into the existing zone-map without Fortimanager trying to delete the existing rules. Is there a way to map a new VLAN interface into an existing VLAN-interface zone-map so we can use the same rule-set? Many thanks, CK
1 REPLY 1
scao_FTNT
Staff
Staff

in 5.0 GA, GUI has check for zone type (single interface zone and normal zone), so when there has device zone mapping or policy pacakge used this zone, then type can not change thus if current zone is single interface zone, you can not add more interface to this zone in 5.0.1, we will try to remove some check and make change zone type easier for most cases in GA, a possible workaround is to run a script on ADOM db, to force to change zone type from single to normal config dynamic interface edit xxx set single-intf disable next end the main difference is, single interface zone will install interface policy to FGT, and change to normal zone will install zone policy to FGT, so you may see many policy delete/re-create during install Thanks Simon
Labels
Top Kudoed Authors