create_firewall_policy
Create a FortiGate firewall policy to permit or block traffic between interfaces, with optional NAT, logging, and security profiles.
Instructions
Create a firewall policy. New policies are added at the end of the list; use move_firewall_policy to reorder. FortiGate-VM evaluation licenses allow only 3 policies.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| nat | No | Source NAT to the outgoing interface IP | |
| name | Yes | Policy name | |
| vdom | No | VDOM (default: FORTIGATE_VDOM, usually root) | |
| extra | No | Extra FortiOS attributes merged into the request body as-is (hyphenated keys) | |
| action | No | accept or deny | |
| status | No | enable or disable | |
| dstaddr | Yes | Destination addresses or groups | |
| dstintf | Yes | Destination interfaces, e.g. [port1] | |
| service | Yes | Services, e.g. [HTTP, HTTPS] or [ALL] | |
| srcaddr | Yes | Source addresses or groups, e.g. [LAB-NET] or [all] | |
| srcintf | Yes | Source interfaces, e.g. [port2] | |
| comments | No | Comment | |
| policyid | No | Policy ID (optional; FortiOS picks the next free ID) | |
| schedule | No | Schedule (default always) | |
| av_profile | No | Antivirus profile ('' to detach) | |
| ips_sensor | No | IPS sensor ('' to detach) | |
| logtraffic | No | all, utm or disable | |
| utm_status | No | Enable security profiles on the policy. Turned on automatically when a profile is given | |
| ssl_ssh_profile | No | SSL/SSH inspection profile: no-inspection, certificate-inspection (hostname/cert visibility, no decryption) or deep-inspection / a custom profile (decrypts; clients must trust the CA) | |
| application_list | No | Application control profile, e.g. default ('' to detach) | |
| webfilter_profile | No | Web filter profile ('' to detach) |