Policy creation
The Fabric Overlay Orchestrator can create firewall policies to allow all traffic through the SD-WAN overlay or create firewall policies just to allow health check traffic through it instead.
When enabling the Fabric Overlay Orchestrator on the root FortiGate device, you have three options for configuring the Policy creation setting: Automatic, Health Check (default), or Manual.
Policy creation option |
Description |
---|---|
Automatic |
Automatically creates policies for the loopback interface and tunnel overlays. |
Health Check (default) |
Automatically creates a policy for the loopback interface so SD-WAN health checks are functional. |
Manual |
No policies are created automatically. |
The Automatic policy creation option creates wildcard allow policies for the tunnel overlays. Therefore, for some cases, these policies do not provide the granularity necessary to restrict overlay traffic to specific subnets or hosts. |
When the Fabric Overlay Orchestrator has already been configured on a device, changing the policy creation rule will create new policies based on the rule but will not delete existing policies. Deleting existing policies must be performed manually. |