This is more request rather than a problem.
Please add copy reverse option when do some nats. That would be very helpful
like anyother firewall has.This is not the correct way to make requests.
But what exactly are you talking about anyway?
I just check some toys from tenda, zyxel, dlink and tplink, no one have that option...like anyother firewall has.
try on FortiGateI just check some toys from tenda, zyxel, dlink and tplink, no one have that option...like anyother firewall has.
"anyother" for me, at this point, not exist.
I do not remember that option on Cisco...
In all these years that I have been working, it has never helped me to copy "the reverse"(¹) of something, also because "on the contrary" would not make sense or would be useless ....
I am not telling you about traffic that is not required, what about computers in the managed server computers group, where it must initiate conversation with each other (for load balacing information sharing for example), and what if there is no internal routes for that kind of traffic (if both server are inside or outside the dmz segnment)? Bi-directional rule is needed than.No your logic is flawed.
A rule is one way on purpose!
If I allow the admin on one vlan, access to a shared printer on another vlan, that means I am allowing traffic ORIGINATING from the admin to access the printer, as desired.
I DO NOT WANT the printer being able to originate and reach the admin as a default rule of any sort. BAD BAD BAD.
Most admins like the concept of BLOCK ALL and only allow traffic the specific explicitly allows.
ALso do not get confused, when I say a one way rule this means the return traffic from the originating request is passed back to the originator. One does not need a return firewall rule to allow the answer to get back to the originator. Its all considered the same session!! The key is where is the traffic originated and where is it going to!
Sorry fortigate guruClone Reverse are not some thing you need to do to make the firewall work. It would be interesting and see you fortigate firewall if you have done that for all your rules???
Its just like anav writes, an option for you to save some click if you need a revers rule to be created.
Reading the manual do help:
https://docs.fortinet.com/document/fort ... ch%20other.
sorry i didnt mean for exclusive leaders firewall devices like tenda, zyxel, dlink and tplinkFortiGate != "anyother"
I don't know if you get it, but I'm not disputing whether the option is useful or not (probably can be useful, why not...),like anyother firewall has.