Fortinet white logo
Fortinet white logo

CLI Reference

config policy

config policy

Description: Configure firewall policies.

config policy

edit <name>

set *srcintf <name1>, <name2>, …

set *dstintf <name1>, <name2>, …

set *srcaddr <name1>, <name2>, …

set dnat [enable | disable]

set *dstaddr <name1>, <name2>, …

set action [accept | deny]

set status [enable | disable]

set *service <name1>, <name2>, …

set nat [enable | disable]

next

delete <name>

move <name1> [after | before] <name2>

end

purge

show

Sample command:

FX201E5919000057 (policy) # show
config firewall policy
    edit test1
        set srcintf lo
        set dstintf any
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status enable
        set service AH
        set nat enable
    next
    edit test2
        set srcintf any
        set dstintf lan
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status disable
        set service ALL
        set nat enable
    next
    edit all-pass
        set srcintf any
        set dstintf any
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status enable
        set service ALL
        set nat enable
    next
end
Parameter Description Type Size Default
srcintf Incoming (ingress) interface. option - none
Option Description
lan LAN as the incoming interface.
lo Loopback as the incoming interface.
lte1 LTE 1 as the incoming interface.
wan WAN as the incoming interface.
port4 Port 4 as the incoming interface.
any Any port as the incoming interface.
dstintf Outgoing (egress) interface. option - none
Option Description
lan LAN as the outgoing interface.
lo Loopback as the outgoing interface.
lte1 LTE 1 as the outgoing interface.
wan WAN as the outgoing interface.
port4 Port 4 as the outgoing interface.
any Any port as the outgoing interface.
srcaddr Source address. option - none
Option Description
all All network addresses.
none None of the network addresses.
lan-src LAN network address.
wan-src WAN network address.
dnat Destination NAT. option - disable
Option Description
enable Enable destination NAT.
disable Disable destination NAT.

dstaddr

Destination address.

option

-

none

Option Description
all All network addresses.
none None of the network addresses.
lan-src LAN network address.
wan-src WAN network address.

action

Policy action.

option

-

accept

Option Description
accept Accept policy.
deny Deny policy.

status

Status of the policy.

option

-

enable

Option Decription
enable Enable this policy.
disable Disable this policy.

service

Service/service group name.

option

-

none

Option Description
ALL All services.
HTTP HTTP service.

etc

Refer to config network service list.

nat

Source NAT.

option

-

disable

Option Description
enable Enable source NAT.
disable Disable source NAT.
FX201E5919000057 (policy) # move test2 after all-pass
FX201E5919000057 (policy) <M> # show
config firewall policy
    edit test1
        set srcintf lo
        set dstintf any
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status enable
        set service AH
        set nat enable
    next
    edit all-pass
        set srcintf any
        set dstintf any
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status enable
        set service ALL
        set nat enable
    next
    edit test2
        set srcintf any
        set dstintf lan
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status disable
        set service ALL
        set nat enable
    next
end

FX201E5919000057 (policy) <M> # end

config policy

config policy

Description: Configure firewall policies.

config policy

edit <name>

set *srcintf <name1>, <name2>, …

set *dstintf <name1>, <name2>, …

set *srcaddr <name1>, <name2>, …

set dnat [enable | disable]

set *dstaddr <name1>, <name2>, …

set action [accept | deny]

set status [enable | disable]

set *service <name1>, <name2>, …

set nat [enable | disable]

next

delete <name>

move <name1> [after | before] <name2>

end

purge

show

Sample command:

FX201E5919000057 (policy) # show
config firewall policy
    edit test1
        set srcintf lo
        set dstintf any
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status enable
        set service AH
        set nat enable
    next
    edit test2
        set srcintf any
        set dstintf lan
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status disable
        set service ALL
        set nat enable
    next
    edit all-pass
        set srcintf any
        set dstintf any
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status enable
        set service ALL
        set nat enable
    next
end
Parameter Description Type Size Default
srcintf Incoming (ingress) interface. option - none
Option Description
lan LAN as the incoming interface.
lo Loopback as the incoming interface.
lte1 LTE 1 as the incoming interface.
wan WAN as the incoming interface.
port4 Port 4 as the incoming interface.
any Any port as the incoming interface.
dstintf Outgoing (egress) interface. option - none
Option Description
lan LAN as the outgoing interface.
lo Loopback as the outgoing interface.
lte1 LTE 1 as the outgoing interface.
wan WAN as the outgoing interface.
port4 Port 4 as the outgoing interface.
any Any port as the outgoing interface.
srcaddr Source address. option - none
Option Description
all All network addresses.
none None of the network addresses.
lan-src LAN network address.
wan-src WAN network address.
dnat Destination NAT. option - disable
Option Description
enable Enable destination NAT.
disable Disable destination NAT.

dstaddr

Destination address.

option

-

none

Option Description
all All network addresses.
none None of the network addresses.
lan-src LAN network address.
wan-src WAN network address.

action

Policy action.

option

-

accept

Option Description
accept Accept policy.
deny Deny policy.

status

Status of the policy.

option

-

enable

Option Decription
enable Enable this policy.
disable Disable this policy.

service

Service/service group name.

option

-

none

Option Description
ALL All services.
HTTP HTTP service.

etc

Refer to config network service list.

nat

Source NAT.

option

-

disable

Option Description
enable Enable source NAT.
disable Disable source NAT.
FX201E5919000057 (policy) # move test2 after all-pass
FX201E5919000057 (policy) <M> # show
config firewall policy
    edit test1
        set srcintf lo
        set dstintf any
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status enable
        set service AH
        set nat enable
    next
    edit all-pass
        set srcintf any
        set dstintf any
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status enable
        set service ALL
        set nat enable
    next
    edit test2
        set srcintf any
        set dstintf lan
        set srcaddr all
        set dnat disable
        set dstaddr all
        set action accept
        set status disable
        set service ALL
        set nat enable
    next
end

FX201E5919000057 (policy) <M> # end