Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sw2090
Honored Contributor

Group Interfaces in Policy to not lose interface pair view?

I need a policy that allows traffic from a load of subnets coming in via a load of ipsec tunnels to access one server with one service. I can build an address group that contains all those subnets and use it in the policy but how about the source interface?

If I set this to "any" the policy will work but I lose the interface pair view in gui which is a bad thing if you have over 1,5k of policies. Is there any way to create a "group" of interfaces to set that as source in the policy in order not to lose pair view?

Also that would enable me to reduce the number of policies on this Fortigate a load :)

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
1 REPLY 1
Toshi_Esumi
SuperUser
SuperUser

We always bind IPSec vpns to a zone even when only one vpn exists. With this way policies look or exactly the same all installations.
Labels
Top Kudoed Authors