Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
catalin_plotogea
New Contributor

FortiGate unable to add loopback interface to zone

Hello,

 

We have couple FGT-300D devices running FortiOS v5.2.6,build711 GA and we are migrating configuration and policies to zone from interfaces (physical and VLANs).  But I an unable to add loopback interfaces to a zone. Loopback if is not referenced in any policies, but still not available to be added to a specific zone. Tried from GUI and CLI.

 

Does this OS have a bug regarding this issues or this is a product design restriction?

 

Thank you!

5 REPLIES 5
emnoc
Esteemed Contributor III

I believe this is a limitation in  FortiOS &  multi-Vdom and nonMulti-Vdom  models running 5.2.x don't allow for loopback type interfaces to be in a zone definition.

 

You can open a case with FTNT support and see what they say.

 

ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
rwpatterson
Valued Contributor III

Technically, a zone isn't an interface, it's a group of interfaces treated equally... Think of it like an address vs an address group in concept, not operation.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
emnoc
Esteemed Contributor III

Yeah, but you still can't install a "loopback" interface into a zone.

 

I'm only aware of the following supported interfaces for a zone concept;

 

[ul]
  • tagged-802.1q
  • tunnel( gre/ipip/ipv6 )
  • vpn-tunnel
  • physical
  • aggregate[/ul]

     

    I believe something has changed over the course of the last major release iirc loopback could be in a zone in  the pass. Some correct me if this is not correct?  I don't have anytihing in  pre 5.0.x to test so I can't prove that theory.

     

    edit: add vdom-interlink to supported interfaces types also for the "zone"

     

     

    Ken

     

     

  • PCNSE 

    NSE 

    StrongSwan  

    PCNSE NSE StrongSwan
    rwpatterson
    Valued Contributor III

    Correct me if I'm wrong. A loopback interface belongs to a device. It is always up and should be reachable by any means allowed by that device's ACL. I just set up a test loopback on my 4.3.17 FGT. There was no provision to apply it to any interface or zone. is that a CLI only option or something?

    Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
    emnoc
    Esteemed Contributor III

    Yes that's a interface that's virtual. I don't think you  can craft ( webgui )  but only from  the  CLI. We used  loopback for SSLVPN portal terminates and sources for logging, ospf,etc....

     

    IIRC maybe in   fortiOS v3.x you could apply a loopback into a zone , but my memory is fogging. In current v5.x you CAN NOT. I think that's what the OP was finding also.

     

    PCNSE 

    NSE 

    StrongSwan  

    PCNSE NSE StrongSwan
    Labels
    Top Kudoed Authors