{"id":2497,"date":"2023-04-26T12:22:24","date_gmt":"2023-04-26T16:22:24","guid":{"rendered":"https:\/\/increasec.com\/?p=2497"},"modified":"2024-05-11T14:23:54","modified_gmt":"2024-05-11T18:23:54","slug":"fortigate-zones-vs-interfaces","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=2497","title":{"rendered":"Fortigate Zones vs Interfaces"},"content":{"rendered":"\n<p>Fortigate v7.0+ (?) allow for Zones.  I usually call my zones Public and Private.  then I can add interfaces to those zones, ie add the WAN interface to the Public zone.<br>When moving to a new ISP you can setup and test the new connection on WAN2, then add WAN2 to the Public Zone.  During a Maintenance window you can Integrate Interface Wan1 to the Public Zone, which will apply all your existing Policies to BOTH WAN ports.<br>If you have multiple WAN connections in a Zone, they need to have the same Route Weight or replies will be routed out the &#8220;Lightest&#8221; interface and firewalls don&#8217;t like asymmetric routing.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"367\" height=\"301\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image.png\" alt=\"\" class=\"wp-image-2591\" style=\"width:216px;height:177px\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image.png 367w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-300x246.png 300w\" sizes=\"auto, (max-width: 367px) 100vw, 367px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"880\" height=\"352\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-1.png\" alt=\"\" class=\"wp-image-2592\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-1.png 880w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-1-300x120.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-1-768x307.png 768w\" sizes=\"auto, (max-width: 880px) 100vw, 880px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"722\" height=\"391\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-2.png\" alt=\"\" class=\"wp-image-2593\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-2.png 722w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-2-300x162.png 300w\" sizes=\"auto, (max-width: 722px) 100vw, 722px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"701\" height=\"880\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-3.png\" alt=\"\" class=\"wp-image-2594\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-3.png 701w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/08\/image-3-239x300.png 239w\" sizes=\"auto, (max-width: 701px) 100vw, 701px\" \/><\/figure>\n\n\n\n<p>PROs:<br>Simplified Rules; if you have multiple WAN interfaces online, your rules can point to a Zone and then a single rule allows traffic through any interface in that zone, avoiding redundant rules.<br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"863\" height=\"333\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-2.png\" alt=\"\" class=\"wp-image-2498\" style=\"width:512px;height:198px\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-2.png 863w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-2-300x116.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-2-768x296.png 768w\" sizes=\"auto, (max-width: 863px) 100vw, 863px\" \/><\/figure>\n\n\n\n<p>CONs:<br>VPNs are still linked to an interface and each Interface has it&#8217;s own IP.  So if the IP named as your VPN target goes down, your VPN is down, unless you created redundant VPNs to each interface.  (FortiOS 7.0)<br><\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"323\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-4-1024x323.png\" alt=\"\" class=\"wp-image-2500\" style=\"width:716px;height:226px\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-4-1024x323.png 1024w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-4-300x95.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-4-768x242.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-4.png 1169w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>When you get to interfaces of a VPN, then we are FORCED to use Zones!  Interfaces are not available if they are in a Zone. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"769\" height=\"264\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-5.png\" alt=\"\" class=\"wp-image-2501\" style=\"width:498px;height:171px\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-5.png 769w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/04\/image-5-300x103.png 300w\" sizes=\"auto, (max-width: 769px) 100vw, 769px\" \/><\/figure>\n\n\n\n<p>You can&#8217;t convert a hardware switch to a Zone<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Conclusion:<br>Ideal time to switch to Zones and simplify your config is during a ISP change.<br>Alway backup your config!<br>Setup an old Fortigate to practice on if you have VPNs as that is a little inconsistent.<br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fortigate v7.0+ (?) allow for Zones. I usually call my zones Public and Private. then I can add interfaces to those zones, ie add the WAN interface to the Public&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[86,4],"class_list":["post-2497","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-fortinet","tag-security"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2497","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2497"}],"version-history":[{"count":6,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2497\/revisions"}],"predecessor-version":[{"id":2904,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/2497\/revisions\/2904"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2497"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}