Fortinet black logo

Examples

Adding SD-WAN zones to policies

Adding SD-WAN zones to policies

You can select SD-WAN zones in a policy. However, you cannot select SD-WAN interface members in a policy.

When you create an SD-WAN zone on the Device Manager > SD-WAN pane, a normalized interface should be automatically created on the Policy & Objects > Object Configurations > Normalized Interfaces pane. The description identifies it as an SD-WAN Zone.

To view normalized interfaces for SD-WAN zones:
  1. Go to Policy & Objects > Object Configurations.
  2. In the tree menu, go to Normalized Interface > Normalized Interface.

    The normalized interface named vpn is displayed that you created on the Device Manager > SD-WAN pane.

To add SD-WAN zones to policies:
  1. Go to Policy & Objects > Policy Packages.
  2. Expand the policy package, and click the firewall policy.

    The firewall policy displays in the content pane.

  3. In the content pane, double-click the firewall policy to open it for editing, and add the SD-WAN zones.

  4. Install the policy package to branch devices.

Adding SD-WAN zones to policies

You can select SD-WAN zones in a policy. However, you cannot select SD-WAN interface members in a policy.

When you create an SD-WAN zone on the Device Manager > SD-WAN pane, a normalized interface should be automatically created on the Policy & Objects > Object Configurations > Normalized Interfaces pane. The description identifies it as an SD-WAN Zone.

To view normalized interfaces for SD-WAN zones:
  1. Go to Policy & Objects > Object Configurations.
  2. In the tree menu, go to Normalized Interface > Normalized Interface.

    The normalized interface named vpn is displayed that you created on the Device Manager > SD-WAN pane.

To add SD-WAN zones to policies:
  1. Go to Policy & Objects > Policy Packages.
  2. Expand the policy package, and click the firewall policy.

    The firewall policy displays in the content pane.

  3. In the content pane, double-click the firewall policy to open it for editing, and add the SD-WAN zones.

  4. Install the policy package to branch devices.