Fortinet white logo
Fortinet white logo

CLI Reference

config system zone

config system zone

Configure zones to group two or more interfaces. When a zone is created you can configure policies for the zone instead of individual interfaces in the zone.

config system zone
    Description: Configure zones to group two or more interfaces. When a zone is created you can configure policies for the zone instead of individual interfaces in the zone.
    edit <name>
        set description {string}
        set fabric-force-sync [enable|disable]
        set fabric-object [enable|disable]
        set fabric-object-source [member|local|...]
        set interface <interface-name1>, <interface-name2>, ...
        set intrazone [allow|deny]
        config tagging
            Description: Config object tagging.
            edit <name>
                set category {string}
                set tags <name1>, <name2>, ...
            next
        end
        set uuid {uuid}
    next
end

config system zone

Parameter

Description

Type

Size

Default

description

Description.

string

Maximum length: 127

fabric-force-sync *

Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped.

option

-

disable

Option

Description

enable

Enable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

disable

Disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

fabric-object *

Security Fabric global object setting.

option

-

disable

Option

Description

enable

Object is set as a security fabric-wide global object.

disable

Object is local to this security fabric member.

fabric-object-source *

Source of truth for fabric object.

option

-

root

Option

Description

member

Source of truth for this object is a non-root member of fabric.

local

Source of truth for this object is this security fabric member.

root

Source of truth for this object is the root of the fabric.

interface <interface-name>

Names of the interfaces that belong to this zone. Interfaces must not be assigned to another zone or have firewall policies defined.

Select interfaces to add to the zone.

string

Maximum length: 79

intrazone

Allow or deny traffic routing between different interfaces in the same zone (default = deny).

option

-

deny

Option

Description

allow

Allow traffic between interfaces in the zone.

deny

Deny traffic between interfaces in the zone.

name

Zone name.

string

Maximum length: 35

uuid *

Universally Unique Identifier (UUID; automatically assigned but can be manually reset).

uuid

Not Specified

00000000-0000-0000-0000-000000000000

* This parameter may not exist in some models.

config tagging

Parameter

Description

Type

Size

Default

category

Tag category.

string

Maximum length: 63

name

Tagging entry name.

string

Maximum length: 63

tags <name>

Tags.

Tag name.

string

Maximum length: 79

config system zone

config system zone

Configure zones to group two or more interfaces. When a zone is created you can configure policies for the zone instead of individual interfaces in the zone.

config system zone
    Description: Configure zones to group two or more interfaces. When a zone is created you can configure policies for the zone instead of individual interfaces in the zone.
    edit <name>
        set description {string}
        set fabric-force-sync [enable|disable]
        set fabric-object [enable|disable]
        set fabric-object-source [member|local|...]
        set interface <interface-name1>, <interface-name2>, ...
        set intrazone [allow|deny]
        config tagging
            Description: Config object tagging.
            edit <name>
                set category {string}
                set tags <name1>, <name2>, ...
            next
        end
        set uuid {uuid}
    next
end

config system zone

Parameter

Description

Type

Size

Default

description

Description.

string

Maximum length: 127

fabric-force-sync *

Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped.

option

-

disable

Option

Description

enable

Enable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

disable

Disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

fabric-object *

Security Fabric global object setting.

option

-

disable

Option

Description

enable

Object is set as a security fabric-wide global object.

disable

Object is local to this security fabric member.

fabric-object-source *

Source of truth for fabric object.

option

-

root

Option

Description

member

Source of truth for this object is a non-root member of fabric.

local

Source of truth for this object is this security fabric member.

root

Source of truth for this object is the root of the fabric.

interface <interface-name>

Names of the interfaces that belong to this zone. Interfaces must not be assigned to another zone or have firewall policies defined.

Select interfaces to add to the zone.

string

Maximum length: 79

intrazone

Allow or deny traffic routing between different interfaces in the same zone (default = deny).

option

-

deny

Option

Description

allow

Allow traffic between interfaces in the zone.

deny

Deny traffic between interfaces in the zone.

name

Zone name.

string

Maximum length: 35

uuid *

Universally Unique Identifier (UUID; automatically assigned but can be manually reset).

uuid

Not Specified

00000000-0000-0000-0000-000000000000

* This parameter may not exist in some models.

config tagging

Parameter

Description

Type

Size

Default

category

Tag category.

string

Maximum length: 63

name

Tagging entry name.

string

Maximum length: 63

tags <name>

Tags.

Tag name.

string

Maximum length: 79