Fortinet Document Library

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:


Table of Contents

Administration Guide

Modify existing interface-zone mapping

Interfaces mapped to a zone locally on FortiGate devices are not visible in Device Manager on FortiManager. It is recommended to create objects in FortiManager instead of creating it on FortiGate devices locally. If an interface is already mapped to a zone in FortiGate, it must be unmapped first. A zone must be created in FortiManager, added to a policy and installed to FortiGate. For convenience and ease of use, it is better to manage Object Configuration and Interface Mapping from FortiManager.

If an Interface is mapped to a Zone in FortiGate:
  1. Log on to the FortiGate device.
  2. Delete the Interface/Zone mapping from Interfaces > [Interface_Name] > Delete.
  3. Log on to FortiManager.
  4. Create a device zone named Zone_One, and map it to a physical interface:
    1. Go to Device Manager > Device & Groups.
    2. In the tree menu, select a device group. The devices are displayed in the lower tree menu.
    3. In the lower tree menu, double-click a device. The device database is displayed.
    4. Go to System > Interface.
    5. Click Create New > Device Zone.
    6. In the Zone Name box type, Zone_One.
    7. Click the Interface Member box, select one ore more physical interfaces, and click OK. The device zone is created.
  5. Map the device zone to a normalized interface:
    1. Go to Policy & Objects > Object Configurations > Normalized Interface > Normalized Interface.
    2. Click Create New. The Create New Normalized Interface pane is displayed.
    3. In the Name box, type a name for the normalized interface.
    4. Under Per-Device Mapping, click Create New. The Per-Mapping dialog box is displayed.
    5. In the Mapped Device list, select the device.
    6. In the Mapped Interface Name select the device zone that you created, and click OK. The per-device mapping is created.
    7. Click OK. The normalized interface is created and mapped to the device zone.
  6. Create a new policy package named New_Policy_Package.
    1. Go to Policy & Objects > Policy Packages.
    2. From the Policy Package menu, select New.
    3. In the Name box, type a name for the policy package, such as New_Policy_Package.
    4. Set the remaining options, and click OK. The policy package named New_Policy_Package is created.
  7. Create a new policy for the policy package, and select the device zone.
    1. In the tree menu, select the new policy package, for example, the policy package named New_Policy_Package, and click Create New. The Create New Firewall Policy pane is displayed.
    2. In the Name box, type a name, such as New_IPv4_Policy.
    3. Include Zone_One in the policy, and click OK. The policy is saved.
  8. Assign the policy package to the device:
    1. In the tree menu, expand New_Policy_Package, and click Installation Targets.
    2. Click Edit, select the FortiGate, and click OK.
  9. Install the policy package to the FortiGate:
    1. Right-click New_Policy_Package, and select Install Wizard.
    2. Select Install Policy Package & Device Settings, and select the New_Policy_Package from the drop-down.
    3. Complete the installation as per the Install Wizard.

    Zone_One is now available on the FortiGate device and mapped.

note icon

A zone is installed to a FortiGate device only if it is created, mapped to an interface, included in the Policy Package, assigned to a device, and installed using the Install Wizard.

note icon

An interface cannot be reused if it is already mapped to a zone. To reuse an interface, first unmap it from the zone in Object Configurations, and then reinstall to the FortiGate device.

note icon

After a Virtual IP is created, it must be mapped to interfaces. If per-device mapping is used, the mapping will be visible immediately in Device Manager > [ Device_Name] > Interface.

Modify existing interface-zone mapping

Interfaces mapped to a zone locally on FortiGate devices are not visible in Device Manager on FortiManager. It is recommended to create objects in FortiManager instead of creating it on FortiGate devices locally. If an interface is already mapped to a zone in FortiGate, it must be unmapped first. A zone must be created in FortiManager, added to a policy and installed to FortiGate. For convenience and ease of use, it is better to manage Object Configuration and Interface Mapping from FortiManager.

If an Interface is mapped to a Zone in FortiGate:
  1. Log on to the FortiGate device.
  2. Delete the Interface/Zone mapping from Interfaces > [Interface_Name] > Delete.
  3. Log on to FortiManager.
  4. Create a device zone named Zone_One, and map it to a physical interface:
    1. Go to Device Manager > Device & Groups.
    2. In the tree menu, select a device group. The devices are displayed in the lower tree menu.
    3. In the lower tree menu, double-click a device. The device database is displayed.
    4. Go to System > Interface.
    5. Click Create New > Device Zone.
    6. In the Zone Name box type, Zone_One.
    7. Click the Interface Member box, select one ore more physical interfaces, and click OK. The device zone is created.
  5. Map the device zone to a normalized interface:
    1. Go to Policy & Objects > Object Configurations > Normalized Interface > Normalized Interface.
    2. Click Create New. The Create New Normalized Interface pane is displayed.
    3. In the Name box, type a name for the normalized interface.
    4. Under Per-Device Mapping, click Create New. The Per-Mapping dialog box is displayed.
    5. In the Mapped Device list, select the device.
    6. In the Mapped Interface Name select the device zone that you created, and click OK. The per-device mapping is created.
    7. Click OK. The normalized interface is created and mapped to the device zone.
  6. Create a new policy package named New_Policy_Package.
    1. Go to Policy & Objects > Policy Packages.
    2. From the Policy Package menu, select New.
    3. In the Name box, type a name for the policy package, such as New_Policy_Package.
    4. Set the remaining options, and click OK. The policy package named New_Policy_Package is created.
  7. Create a new policy for the policy package, and select the device zone.
    1. In the tree menu, select the new policy package, for example, the policy package named New_Policy_Package, and click Create New. The Create New Firewall Policy pane is displayed.
    2. In the Name box, type a name, such as New_IPv4_Policy.
    3. Include Zone_One in the policy, and click OK. The policy is saved.
  8. Assign the policy package to the device:
    1. In the tree menu, expand New_Policy_Package, and click Installation Targets.
    2. Click Edit, select the FortiGate, and click OK.
  9. Install the policy package to the FortiGate:
    1. Right-click New_Policy_Package, and select Install Wizard.
    2. Select Install Policy Package & Device Settings, and select the New_Policy_Package from the drop-down.
    3. Complete the installation as per the Install Wizard.

    Zone_One is now available on the FortiGate device and mapped.

note icon

A zone is installed to a FortiGate device only if it is created, mapped to an interface, included in the Policy Package, assigned to a device, and installed using the Install Wizard.

note icon

An interface cannot be reused if it is already mapped to a zone. To reuse an interface, first unmap it from the zone in Object Configurations, and then reinstall to the FortiGate device.

note icon

After a Virtual IP is created, it must be mapped to interfaces. If per-device mapping is used, the mapping will be visible immediately in Device Manager > [ Device_Name] > Interface.