Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Holy
Contributor

Intra Zone Routing

Hello everyone, if i put 2 or more Interfaces into a Zone and allow Intra Zone Routing. How can i enable any UTM Features for this Connections? or is it allways like Any - Any and without UTM features? Thank you in Advance

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
5 REPLIES 5
ede_pfau
SuperUser
SuperUser

AFAIK there is no UTM applied for intrazone traffic. If you need it, create policies between interfaces (yes I know, this can be a " n x (n-1)" task).

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
netmin
Contributor II

I would add: in order to have policies (zone interface to zone interface, i.e. subnet A to subnet B) working, intra-zone traffic needs to be blocked.
Holy

Hello, thank for the answers. but if i do create a zone, i cant choose the interfaces when creating a Policy that belongs to this Zone. So I created a Zone called Test_Zone and added 2 Interfaces Port8 , Port9 to this Zone, i blooked intra-zone traffic. now I can create a Policy with the incoming Interface " Test_Zone" and outgoing Interface " Test_Zone" . but i cant create a Policy with Interface port 8 to interface Port 9. So how can i set UTM Features if i wish to communicate from port 8 to port 9 ? what if i have more than 2 interfaces in my zone? thank you in Advance

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
netmin
Contributor II

It is intended to work this way (zone to zone policy), so you would need to create address objects (i.e. subnets or IP address ranges) and specify them in source and destination accordingly.
Holy

now i get it. will try it out, thank you very much.

NSE 8 

NSE 1 - 7

 

NSE 8 NSE 1 - 7
Labels
Top Kudoed Authors