Create a new hyperscale policy
In FortiManager, you can create hyperscale policies by configuring the policy package's policy offload level to Full Offload and enabling the policy types in the Display Options. For more information on hyperscale firewalls, see the FortiOS Hyperscale Firewall Guide.
Hyperscale policies are only available on limited FortiGates with a hyperscale firewall license. Hyperscale policies must be enabled before they can be used. On the Policy & Objects pane, from the Tools menu, select Display Options and then select the hyperscale policy checkboxes to display these options, if available. |
To use hyperscale policies in a policy package:
- Go to Policy & Objects in supported a ADOM version on FortiManager.
- Create a new policy package, or right click an existing policy package from the tree menu, and select Edit.
- Under the Policy Offload Level option, select Full Offload, and click OK.
Hyperscale policy types enabled in Display Options are now available in the policy package.
To configure a hyperscale policy:
- If using ADOMs, ensure that you are in the correct ADOM.
- Go to Policy & Objects > Policy Packages.
- In the tree menu for the policy package click the selected hyperscale policy.
- Click Create New.
- Enter the following information:
Option
Description
Name Enter a unique name for the policy. Each policy must have a unique name. Incoming Interface Click the field then select interfaces.Click the remove icon to remove interfaces. Outgoing Interface Select outgoing interfaces in the same manner as Incoming Interface. Source Address
Select source addresses, address groups, virtual IPs, and virtual IP groups.
Destination Address
Select destination addresses, address groups, virtual IPs, and virtual IP groups.
Service
Select services and service groups.
Action
Select an action for the policy to take: DENY or ACCEPT.
Comments
Add a description of the policy, such as its purpose, or the changes that have been made to it.
Advanced Options
Expand to view and configure advanced options for the policy.
Change Note
Add a description of the changes being made to the policy. This field is required. When configuring a Hyperscale Policy, there are fields to define IPv4 and IPv6 source addresses and destination addresses.
- Click OK to create the policy. You can select to enable or disable the policy in the right-click menu. When disabled, a disabled icon will be displayed in the Seq.# column to the left of the number. By default, policies will be added to the bottom of the list, but above the implicit policy.