Fortinet black logo

Administration Guide

Creating normalized interfaces

Creating normalized interfaces

If you want to use a physical interface name in a per-platform mapping rule in a normalized interface, you must first delete the default per-platform mapping rule from the default per-platform interface. Otherwise the dynamic-interface default mapping has been used error is displayed, and you cannot create the normalized interface.

To delete the default per-platform mapping rule:
  1. Go to Policy & Objects > Object Configurations > Normalized Interface > Normalized Interface.
  2. In the content pane, right-click the default per-platform normalized interface, and select Edit.

    The Edit Normalized Interface page appears.

  3. In the Per-Platform Mapping table, right-click the default per-platform mapping rule, and select Delete.
  4. Click OK.
To create normalized interfaces for zones:
  1. Go to Policy & Objects > Object Configurations > Normalized Interface > Normalized Interface.
  2. Click Create New.

    The Create New Normalized Interface pane is displayed.

  3. Complete the Name, Description, and Color options.
  4. Add a per-platform mapping.
    1. Toggle Per-Platform Mapping to ON.

      The Per-Platform Mapping table is displayed.

    2. Click Create New.

      The Create new Per-Platform Mapping dialog box is displayed.

    3. In the Model list, select the model for which you created the zone.
    4. In the Device Interface Name box, type the name of the interface.
    5. Click OK.
  5. Add a per-device mapping.
    1. Toggle Per-Device Mapping to ON.

      The Per-Device Mapping table is displayed.

    2. Click Create New.

      The Create new Per-Device Mapping dialog box is displayed.

    3. In the Mapped Device list, select the model for which you created the zone.
    4. In the Device Interface list, select the zone.
    5. Click OK.
  6. Click OK.
To create a wildcard interface:
  1. Go to Policy & Objects > Object Configurations > Normalized Interface > Normalized Interface.
  2. Click Create New.

    The Create New Normalized Interface pane is displayed.

  3. Complete the Name, Description, and Color options.
  4. Set the Wildcard toggle to the ON position, and enter the Wildcard Interface in the text field below.
    Note

    When using wildcards, a "." (period) represents a single alpha-numeric character, similar to regex = [a-zA-Z0-9].

    An "*" (asterisk) represents zero or more characters regex =.*

  5. Add a Change Note and click OK.
    The wildcard interface can be used in Firewall policies similar to a regular interface but will be interpreted as one or more interfaces that matched the defined wildcard pattern.
    During install, all matched objects are installed.

Creating normalized interfaces

If you want to use a physical interface name in a per-platform mapping rule in a normalized interface, you must first delete the default per-platform mapping rule from the default per-platform interface. Otherwise the dynamic-interface default mapping has been used error is displayed, and you cannot create the normalized interface.

To delete the default per-platform mapping rule:
  1. Go to Policy & Objects > Object Configurations > Normalized Interface > Normalized Interface.
  2. In the content pane, right-click the default per-platform normalized interface, and select Edit.

    The Edit Normalized Interface page appears.

  3. In the Per-Platform Mapping table, right-click the default per-platform mapping rule, and select Delete.
  4. Click OK.
To create normalized interfaces for zones:
  1. Go to Policy & Objects > Object Configurations > Normalized Interface > Normalized Interface.
  2. Click Create New.

    The Create New Normalized Interface pane is displayed.

  3. Complete the Name, Description, and Color options.
  4. Add a per-platform mapping.
    1. Toggle Per-Platform Mapping to ON.

      The Per-Platform Mapping table is displayed.

    2. Click Create New.

      The Create new Per-Platform Mapping dialog box is displayed.

    3. In the Model list, select the model for which you created the zone.
    4. In the Device Interface Name box, type the name of the interface.
    5. Click OK.
  5. Add a per-device mapping.
    1. Toggle Per-Device Mapping to ON.

      The Per-Device Mapping table is displayed.

    2. Click Create New.

      The Create new Per-Device Mapping dialog box is displayed.

    3. In the Mapped Device list, select the model for which you created the zone.
    4. In the Device Interface list, select the zone.
    5. Click OK.
  6. Click OK.
To create a wildcard interface:
  1. Go to Policy & Objects > Object Configurations > Normalized Interface > Normalized Interface.
  2. Click Create New.

    The Create New Normalized Interface pane is displayed.

  3. Complete the Name, Description, and Color options.
  4. Set the Wildcard toggle to the ON position, and enter the Wildcard Interface in the text field below.
    Note

    When using wildcards, a "." (period) represents a single alpha-numeric character, similar to regex = [a-zA-Z0-9].

    An "*" (asterisk) represents zero or more characters regex =.*

  5. Add a Change Note and click OK.
    The wildcard interface can be used in Firewall policies similar to a regular interface but will be interpreted as one or more interfaces that matched the defined wildcard pattern.
    During install, all matched objects are installed.