Fortinet white logo
Fortinet white logo

Administration Guide

Hyperscale policies

Hyperscale policies

In FortiManager, you can create hyperscale policies by configuring the policy package's policy offload level to Full Offload and enabling the policy types in the Display Options. For more information on hyperscale firewalls, see the FortiGate Administration Guide.

Some hyperscale policy types must be enabled before they can be used. On the Policy & Objects pane, from the Tools menu, select Display Options, and then select the hyperscale policy checkboxes to display these options.

Note

Hyperscale policies are available in 6.2 and 6.4 ADOMs:

  • 6.4 ADOMs support hyperscale policies, NAT46 hyperscale policies, and NAT 64 hyperscale policies.
  • 6.2 ADOMs support IPv4 hyperscale policies, NAT46 hyperscale policies, NAT 64 hyperscale policies, and IPv6 hyperscale policies.
To use hyperscale policies in a policy package:
  1. Go to Policy & Objects in supported a ADOM version on FortiManager.
  2. Create a new policy package, or right click an existing policy package from the tree menu, and select Edit.
  3. Under the Policy Offload Level option, select Full Offload, and click OK.
    Hyperscale policy types enabled in Display Options are now available in the policy package.
To configure a hyperscale policy:
  1. Ensure you are in the correct ADOM.
  2. Go to Policy & Objects > Policy Packages.
  3. In the tree menu for the policy package, click the selected hyperscale policy.
  4. Click Create New, or, from the Create New menu, select Insert Above or Insert Below. By default, policies will be added to the bottom of the list. The Create New Policy pane opens.
  5. Configure the hyperscale policy settings, then click OK to create the policy:
    NameEnter a name for the policy.
    Incoming InterfaceSelect the incoming interface.
    Outgoing InterfaceSelect the outgoing interface.

    Source Address

    Select the source address.

    Destination Address

    Select the destination address.

    Service

    Select services and service groups.

    Action

    Select an action for the policy to take: ACCEPT or DENY.

    Comments

    Optionally, enter comments about the policy.

    Advanced Options

    Expand to view advanced options for the policy.

    Note

    When configuring a Hyperscale Policy in 6.4 ADOMs, there are fields to define IPv4 and IPv6 source addresses and destination addresses.

Hyperscale policies

Hyperscale policies

In FortiManager, you can create hyperscale policies by configuring the policy package's policy offload level to Full Offload and enabling the policy types in the Display Options. For more information on hyperscale firewalls, see the FortiGate Administration Guide.

Some hyperscale policy types must be enabled before they can be used. On the Policy & Objects pane, from the Tools menu, select Display Options, and then select the hyperscale policy checkboxes to display these options.

Note

Hyperscale policies are available in 6.2 and 6.4 ADOMs:

  • 6.4 ADOMs support hyperscale policies, NAT46 hyperscale policies, and NAT 64 hyperscale policies.
  • 6.2 ADOMs support IPv4 hyperscale policies, NAT46 hyperscale policies, NAT 64 hyperscale policies, and IPv6 hyperscale policies.
To use hyperscale policies in a policy package:
  1. Go to Policy & Objects in supported a ADOM version on FortiManager.
  2. Create a new policy package, or right click an existing policy package from the tree menu, and select Edit.
  3. Under the Policy Offload Level option, select Full Offload, and click OK.
    Hyperscale policy types enabled in Display Options are now available in the policy package.
To configure a hyperscale policy:
  1. Ensure you are in the correct ADOM.
  2. Go to Policy & Objects > Policy Packages.
  3. In the tree menu for the policy package, click the selected hyperscale policy.
  4. Click Create New, or, from the Create New menu, select Insert Above or Insert Below. By default, policies will be added to the bottom of the list. The Create New Policy pane opens.
  5. Configure the hyperscale policy settings, then click OK to create the policy:
    NameEnter a name for the policy.
    Incoming InterfaceSelect the incoming interface.
    Outgoing InterfaceSelect the outgoing interface.

    Source Address

    Select the source address.

    Destination Address

    Select the destination address.

    Service

    Select services and service groups.

    Action

    Select an action for the policy to take: ACCEPT or DENY.

    Comments

    Optionally, enter comments about the policy.

    Advanced Options

    Expand to view advanced options for the policy.

    Note

    When configuring a Hyperscale Policy in 6.4 ADOMs, there are fields to define IPv4 and IPv6 source addresses and destination addresses.