Hot!Group Interfaces in Policy to not lose interface pair view?

Author
sw2090
Gold Member
  • Total Posts : 370
  • Scores: 21
  • Reward points: 0
  • Joined: 2017/06/14 01:27:25
  • Location: Regensburg
  • Status: offline
2019/06/11 07:16:47 (permalink)
0

Group Interfaces in Policy to not lose interface pair view?

I need a policy that allows traffic from a load of subnets coming in via a load of ipsec tunnels to access one server with one service. I can build an address group that contains all those subnets and use it in the policy but how about the source interface?
If I set this to "any" the policy will work but I lose the interface pair view in gui which is a bad thing if you have over 1,5k of policies. Is there any way to create a "group" of interfaces to set that as source in the policy in order not to lose pair view?
Also that would enable me to reduce the number of policies on this Fortigate a load :)
#1

1 Reply Related Threads

    Toshi Esumi
    Expert Member
    • Total Posts : 1623
    • Scores: 137
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: Group Interfaces in Policy to not lose interface pair view? 2019/06/11 08:05:09 (permalink)
    0
    We always bind IPSec vpns to a zone even when only one vpn exists. With this way policies look or exactly the same all installations.
    #2
    Jump to:
    © 2019 APG vNext Commercial Version 5.5