Creating a policy
You can create new central policies from the SDWan Overlay > Overlay Policy page.
To create a new policy:
-
Go to SDWan Overlay > Overlay Policy.
-
Click Create.
-
Enter a Name.
-
Define the source:
-
To define a source address, select Address:
-
Select the Site from the dropdown list.
-
Select the Interface from the dropdown list.
-
Select the Address from the dropdown list.
You can create a new address in the SDWan Overlay > Addresses page. See Creating an address.
-
-
To define a source address group, select Address Group:
-
Select the Address group from the dropdown menu.
If there are no address groups listed, you can create a new address group in the SDWan Overlay > Addresses page. See Creating an address group.
-
-
- Define the destination:
To define a destination address, select Address:
Select the Site from the dropdown list.
Select the Interface from the dropdown list.
Select the Address from the dropdown list.

You can create a new address in the SDWan Overlay > Addresses page. See Creating an address.
To define a destination address group, select Address Group:
Select the Address Group from the dropdown menu.

If there are no address groups listed, you can create a new address group in the SDWan Overlay > Addresses page. See Creating an address group.
-
Select the Service.
You can create a new service in the SDWan Overlay > Services page. See Creating a service.
-
Select the Service Group.
If there are no service groups listed, you can create a new service group in the SDWan Overlay > Services page. See Creating a service group.
-
Define the schedule of the policy:
-
To define the schedule, select Schedule:
-
Select the Schedule from the dropdown list.
You can create a new schedule in the SDWan Overlay > Schedules page. See Creating a recurring schedule and Creating a one-time schedule.
-
-
To define the schedule group, select Schedule Group:
-
Select the Schedule Group from the dropdown list.
If there are no schedule groups listed, you can create a new schedule group in the SDWan Overlay > Schedules page. See Creating a schedule group.
-
-
-
Set the Action as accept or deny.
-
Select the Security Profiles.
Security profiles can be configured in the SDWan Overlay > Security profiles page. See Security profiles.
-
Define the Logging Options:
-
Toggle Log Allowed Traffic and select Security Events or All Sessions to define which events to log.
-
Enable Generate Logs when Session Starts, if needed.
-
-
(Optional) Enter a description for the policy.
-
Toggle Enable this policy to enable or disable the policy.
-
Click OK.
Once a policy has been created, it will appear in the SDWan Overlay > Overlay policy list with the new status. You must save and apply the policy to the spoke FortiGates before they will take effect. See Applying policies.