Fortinet white logo
Fortinet white logo

NGFW to SPA Hub Conversion Using Fabric Overlay Orchestrator

Policy creation

Policy creation

The Fabric Overlay Orchestrator can create firewall policies to allow all traffic through the SD-WAN overlay or create firewall policies just to allow health check traffic through it instead.

When enabling the Fabric Overlay Orchestrator on the root FortiGate device, you have three options for configuring the Policy creation setting: Automatic, Health Check (default), or Manual.

Policy creation option

Description

Automatic

Automatically creates policies for the loopback interface and tunnel overlays.

Health Check (default)

Automatically creates a policy for the loopback interface so SD-WAN health checks are functional.

Manual

No policies are created automatically.

Note

The Automatic policy creation option creates wildcard allow policies for the tunnel overlays. Therefore, for some cases, these policies do not provide the granularity necessary to restrict overlay traffic to specific subnets or hosts.

Note

When the Fabric Overlay Orchestrator has already been configured on a device, changing the policy creation rule will create new policies based on the rule but will not delete existing policies. Deleting existing policies must be performed manually.

Policy creation

Policy creation

The Fabric Overlay Orchestrator can create firewall policies to allow all traffic through the SD-WAN overlay or create firewall policies just to allow health check traffic through it instead.

When enabling the Fabric Overlay Orchestrator on the root FortiGate device, you have three options for configuring the Policy creation setting: Automatic, Health Check (default), or Manual.

Policy creation option

Description

Automatic

Automatically creates policies for the loopback interface and tunnel overlays.

Health Check (default)

Automatically creates a policy for the loopback interface so SD-WAN health checks are functional.

Manual

No policies are created automatically.

Note

The Automatic policy creation option creates wildcard allow policies for the tunnel overlays. Therefore, for some cases, these policies do not provide the granularity necessary to restrict overlay traffic to specific subnets or hosts.

Note

When the Fabric Overlay Orchestrator has already been configured on a device, changing the policy creation rule will create new policies based on the rule but will not delete existing policies. Deleting existing policies must be performed manually.