Created on 06-09-2023 07:58 AM Edited on 10-09-2023 06:03 AM By Jean-Philippe_P
Description | This article explains the difference between 'srcintf-filter' and 'extintf' in the VIP settings. |
Scope | FortiOS, FortiProxy. |
Solution |
'srcintf-filter' and 'extintf' definitions in the VIP settings often bring confusion.
'extintf' is intended to be used as a WebGUI improvement tool. Defining an interface as a value of extintf parameter will make sure that the FortiGate will do the DNAT translation based on the configured VIP object for traffic coming from the selected interface.
Example:
config firewall VIP
With this configuration, on WebGUI, that VIP will be available for selection only if wan1 is configured as a source interface.
extintf will not bind the VIP to the specific interface. That means that the VIP shown as an example above will accept connections from each and every interface.
config firewall VIP
srcintf-filter is helpful in the setup of failover IPSec tunnel with overlapping subnets to prevent creating separate IP pools and VIP objects for each IPsec tunnel. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.