Firewall configuration

Centralized access is controlled from the hub FortiGate using Firewall policies. In addition to layer three and four inspection, security policies can be used in the policies for layer seven traffic inspection.

It is best practice to only allow the networks and services that are required for communication through the firewall. The following rules are the minimum that must be configured to allow SD-WAN to function:

Source Interface

Destination Interface

Source Address

Destination Address

Action

Schedule

Service

Comments

<internal interface>

<virtual wan link>

<branch networks>

<datacenter networks>