{"id":221,"date":"2026-08-03T23:21:10","date_gmt":"2026-08-03T17:51:10","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/"},"modified":"2026-09-14T04:41:11","modified_gmt":"2026-09-13T23:11:11","slug":"configure-interfaces-and-firewall-policies-on-a-fortigate-firewall","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/","title":{"rendered":"How to Configure Interfaces and Firewall Policies on a FortiGate Firewall"},"content":{"rendered":"<p>Setting up a new firewall requires establishing network connectivity before implementing security control. FortiGate appliances operate on a zero-trust model by default. Every physical or logical interface drops all incoming and outgoing traffic until you explicitly assign IP addresses, configure routing, and create security policies. Understanding how to configure <strong>FortiGate interfaces and firewall policies<\/strong> forms the foundation of modern network engineering.<\/p>\n<p>In this guide, you will learn how to configure network interfaces, establish static routing, construct firewall policies, and enable Source Network Address Translation (SNAT). Furthermore, we will walk through packet flow dynamics, verification techniques, and flow debugging workflows.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>A corporate enterprise is deploying a new FortiGate appliance at a remote branch office. The local Internet Service Provider (ISP) delivered a static public IPv4 subnet. The internal operations team created a local network for branch workstations.<\/p>\n<p>Your objective is to connect the branch office to the internet safely. You must configure the internet-facing WAN interface and the internal LAN interface. Additionally, you must build a static default route toward the ISP, create address objects for the subnet, and configure an outbound firewall policy with NAT enabled. The firewall must permit internal users to reach public resources while blocking unauthorized inbound connections from the internet.<\/p>\n<h2>Lab Topology<\/h2>\n<p>The network topology for this scenario contains a single FortiGate unit positioned between the ISP edge router and the local branch network. All IP addresses used in this tutorial are standard documentation addresses reserved for demonstration purposes.<\/p>\n<pre>\n                      +-------------------+\n                      |     Internet      |\n                      +---------+---------+\n                                |\n                                | Public IPv4: 203.0.113.1\/24\n                        [ ISP Gateway Router ]\n                                |\n                                | Public IPv4: 203.0.113.10\/24\n                       +--------+--------+\n                       |   port1 (WAN)   |\n                       |                 |\n                       |    FortiGate    |\n                       |                 |\n                       |   port2 (LAN)   |\n                       +--------+--------+\n                                | Internal Gateway: 192.0.2.1\/24\n                                |\n                        [ Layer 2 Switch ]\n                                |\n                                | Subnet: 192.0.2.0\/24\n                        +-------+-------+\n                        |  Branch Client |\n                        | (192.0.2.50)  |\n                        +---------------+\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>The following table details the network addressing scheme and firewall configuration parameters used throughout this lab environment.<\/p>\n<table>\n<thead>\n<tr>\n<th>Parameter \/ Object<\/th>\n<th>Type \/ Interface<\/th>\n<th>Configured Value<\/th>\n<th>Description \/ Role<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>port1<\/code><\/td>\n<td>Physical Interface<\/td>\n<td><code>203.0.113.10\/24<\/code><\/td>\n<td>WAN Interface (Connected to ISP)<\/td>\n<\/tr>\n<tr>\n<td><code>port2<\/code><\/td>\n<td>Physical Interface<\/td>\n<td><code>192.0.2.1\/24<\/code><\/td>\n<td>LAN Interface (Default Gateway for Branch)<\/td>\n<\/tr>\n<tr>\n<td>Default Route<\/td>\n<td>Static Route<\/td>\n<td><code>0.0.0.0\/0<\/code> via <code>203.0.113.1<\/code><\/td>\n<td>Egress routing table entry for external traffic<\/td>\n<\/tr>\n<tr>\n<td><code>LAN_Subnet<\/code><\/td>\n<td>Address Object<\/td>\n<td><code>192.0.2.0\/255.255.255.0<\/code><\/td>\n<td>Firewall object representing internal network<\/td>\n<\/tr>\n<tr>\n<td><code>LAN_to_WAN_Outbound<\/code><\/td>\n<td>Firewall Policy<\/td>\n<td>Src: <code>port2<\/code> \/ Dst: <code>port1<\/code><\/td>\n<td>Stateful access rule allowing internet outbound<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<ul>\n<li>Administrative access to a FortiGate firewall running FortiOS version 7.x via Web GUI or CLI.<\/li>\n<li>Basic understanding of IPv4 routing, subnetting, and stateful inspection concepts.<\/li>\n<li>Unused network interfaces (referred to as <code>port1<\/code> and <code>port2<\/code> in standard desktop\/rack models).<\/li>\n<li>Assigned IP parameters from your ISP and internal IP allocation plans.<\/li>\n<\/ul>\n<p><em>Note: FortiOS menu structures and command syntax may vary slightly depending on your hardware model, virtual domain (VDOM) configuration, feature visibility switches, and software version. Adapt these lab values to match your specific production environment.<\/em><\/p>\n<h2>Step-by-Step GUI Configuration<\/h2>\n<h3>Step 1: Configure the WAN Interface<\/h3>\n<p>First, configure the external interface connecting to the service provider.<\/p>\n<ol>\n<li>Log in to the FortiGate Web GUI.<\/li>\n<li>Navigate to <strong>Network &gt; Interfaces<\/strong>.<\/li>\n<li>Select <strong>port1<\/strong> and click <strong>Edit<\/strong> (or double-click the row).<\/li>\n<li>Set the <strong>Alias<\/strong> to <code>WAN_ISP1<\/code> to clearly mark the interface usage.<\/li>\n<li>Set <strong>Role<\/strong> to <code>WAN<\/code>.<\/li>\n<li>Under <strong>Addressing Mode<\/strong>, select <strong>Manual<\/strong>.<\/li>\n<li>In the <strong>IP\/Netmask<\/strong> field, enter <code>203.0.113.10\/255.255.255.0<\/code> (or <code>203.0.113.10\/24<\/code>).<\/li>\n<li>Under <strong>Administrative Access<\/strong>, enable only <code>PING<\/code> for diagnostic tests. Keep management protocols like <code>HTTPS<\/code> and <code>SSH<\/code> disabled on public WAN interfaces.<\/li>\n<li>Click <strong>OK<\/strong> to save the configuration.<\/li>\n<\/ol>\n<h3>Step 2: Configure the LAN Interface<\/h3>\n<p>Next, configure the internal interface serving local branch clients.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; Interfaces<\/strong>.<\/li>\n<li>Select <strong>port2<\/strong> and click <strong>Edit<\/strong>.<\/li>\n<li>Set the <strong>Alias<\/strong> to <code>LAN_Internal<\/code>.<\/li>\n<li>Set <strong>Role<\/strong> to <code>LAN<\/code>.<\/li>\n<li>Under <strong>Addressing Mode<\/strong>, select <strong>Manual<\/strong>.<\/li>\n<li>In the <strong>IP\/Netmask<\/strong> field, enter <code>192.0.2.1\/255.255.255.0<\/code>.<\/li>\n<li>Under <strong>Administrative Access<\/strong>, select <code>HTTPS<\/code>, <code>SSH<\/code>, and <code>PING<\/code> to allow secure internal management access.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 3: Configure the Static Default Route<\/h3>\n<p>Without an outbound route, the FortiGate cannot forward egress packets to external destination addresses.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; Static Routes<\/strong>.<\/li>\n<li>Click <strong>Create New<\/strong>.<\/li>\n<li>Leave the <strong>Destination<\/strong> set to <code>Subnet<\/code> with <code>0.0.0.0\/0.0.0.0<\/code> (quad-zero default route).<\/li>\n<li>In the <strong>Gateway Address<\/strong> field, enter <code>203.0.113.1<\/code> (the ISP upstream router IP).<\/li>\n<li>Set the <strong>Interface<\/strong> dropdown to <code>port1<\/code> (or <code>WAN_ISP1<\/code>).<\/li>\n<li>Keep administrative distance set to the default value of <code>10<\/code>.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 4: Create the Internal Network Address Object<\/h3>\n<p>Define reusable firewall objects to specify matching criteria within your security policy rules.<\/p>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; Addresses<\/strong>.<\/li>\n<li>Click <strong>Create New<\/strong> and select <strong>Address<\/strong>.<\/li>\n<li>Enter <code>LAN_Subnet<\/code> in the <strong>Name<\/strong> field.<\/li>\n<li>Set <strong>Type<\/strong> to <code>Subnet<\/code>.<\/li>\n<li>In the <strong>IP\/Netmask<\/strong> field, enter <code>192.0.2.0\/24<\/code> (or <code>192.0.2.0\/255.255.255.0<\/code>).<\/li>\n<li>Set <strong>Associated Interface<\/strong> to <code>port2<\/code> (or leave as <code>Any<\/code>).<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 5: Create the Firewall Policy<\/h3>\n<p>Finally, tie the interfaces, address objects, and translation rules together into an active policy rule.<\/p>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; Firewall Policy<\/strong>.<\/li>\n<li>Click <strong>Create New<\/strong>.<\/li>\n<li>Configure the policy options as follows:\n<ul>\n<li><strong>Name:<\/strong> <code>LAN_to_WAN_Outbound<\/code><\/li>\n<li><strong>Incoming Interface:<\/strong> <code>port2<\/code> (LAN_Internal)<\/li>\n<li><strong>Outgoing Interface:<\/strong> <code>port1<\/code> (WAN_ISP1)<\/li>\n<li><strong>Source:<\/strong> Select <code>LAN_Subnet<\/code><\/li>\n<li><strong>Destination:<\/strong> Select <code>all<\/code><\/li>\n<li><strong>Schedule:<\/strong> Select <code>always<\/code><\/li>\n<li><strong>Service:<\/strong> Select <code>ALL<\/code> (or restrict to <code>HTTP<\/code>, <code>HTTPS<\/code>, <code>DNS<\/code> depending on security posture)<\/li>\n<li><strong>Action:<\/strong> Select <code>ACCEPT<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Scroll down to the <strong>Firewall \/ Network Options<\/strong> section.<\/li>\n<li>Toggle <strong>NAT<\/strong> to <strong>Enabled<\/strong>.<\/li>\n<li>Ensure <strong>IP Pool Configuration<\/strong> is set to <strong>Use Outgoing Interface Address<\/strong>.<\/li>\n<li>Under <strong>Log Allowed Traffic<\/strong>, select <strong>All Sessions<\/strong> during initial installation to simplify troubleshooting.<\/li>\n<li>Verify that <strong>Enable this policy<\/strong> is switched on.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h2>CLI Section<\/h2>\n<p>For engineers who prefer the Command Line Interface (CLI) via SSH or console access, you can apply the identical configuration using standard FortiOS configuration blocks.<\/p>\n<h3>Configure Interfaces<\/h3>\n<pre><code>config system interface\n    edit \"port1\"\n        set alias \"WAN_ISP1\"\n        set mode static\n        set ip 203.0.113.10 255.255.255.0\n        set allowaccess ping\n        set role wan\n    next\n    edit \"port2\"\n        set alias \"LAN_Internal\"\n        set mode static\n        set ip 192.0.2.1 255.255.255.0\n        set allowaccess ping https ssh\n        set role lan\n    next\nend\n<\/code><\/pre>\n<h3>Configure Static Route<\/h3>\n<pre><code>config router static\n    edit 1\n        set dst 0.0.0.0 0.0.0.0\n        set gateway 203.0.113.1\n        set device \"port1\"\n    next\nend\n<\/code><\/pre>\n<h3>Configure Firewall Address Object<\/h3>\n<pre><code>config firewall address\n    edit \"LAN_Subnet\"\n        set type ipmask\n        set subnet 192.0.2.0 255.255.255.0\n        set associated-interface \"port2\"\n    next\nend\n<\/code><\/pre>\n<h3>Configure Outbound Firewall Policy<\/h3>\n<pre><code>config firewall policy\n    edit 1\n        set name \"LAN_to_WAN_Outbound\"\n        set srcintf \"port2\"\n        set dstintf \"port1\"\n        set action accept\n        set srcaddr \"LAN_Subnet\"\n        set dstaddr \"all\"\n        set schedule \"always\"\n        set service \"ALL\"\n        set nat enable\n        set logtraffic all\n    next\nend\n<\/code><\/pre>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding packet processing within FortiOS helps diagnose communication failures quickly. When an endpoint host at <code>192.0.2.50<\/code> initiates a connection to a web server at <code>198.51.100.25<\/code>, the FortiGate processes the packet through a sequential lifecycle:<\/p>\n<ol>\n<li><strong>Ingress Processing:<\/strong> The frame arrives on <code>port2<\/code>. The FortiGate verifies interface status, checks for valid VLAN tags (if configured), and verifies that ingress security options permit processing.<\/li>\n<li><strong>Routing Table Lookup (FIB Check):<\/strong> The engine examines the destination IP address (<code>198.51.100.25<\/code>). It queries the Forwarding Information Base (FIB) to locate an egress path. The system matches the static default route (<code>0.0.0.0\/0<\/code>) pointing out <code>port1<\/code> via gateway <code>203.0.113.1<\/code>.<\/li>\n<li><strong>Firewall Policy Matching:<\/strong> FortiOS evaluates active firewall policies top-to-bottom. It checks four mandatory criteria:\n<ul>\n<li>Incoming Interface (<code>port2<\/code>)<\/li>\n<li>Outgoing Interface (<code>port1<\/code>)<\/li>\n<li>Source IP (<code>192.0.2.50<\/code> matching <code>LAN_Subnet<\/code>)<\/li>\n<li>Destination IP (<code>198.51.100.25<\/code> matching <code>all<\/code>)<\/li>\n<\/ul>\n<\/li>\n<li><strong>Stateful Session Creation:<\/strong> Upon matching Policy ID 1, FortiOS creates a state entry in the system kernel session table. The firewall tracks connection parameters, TCP sequence numbers, and interface bindings.<\/li>\n<li><strong>Source NAT Application:<\/strong> Because Policy ID 1 has NAT enabled using the egress interface mode, the kernel rewrites the IP header. The original source IP (<code>192.0.2.50<\/code>) changes to the WAN interface IP (<code>203.0.113.10<\/code>). It assigns a unique source port for translation tracking.<\/li>\n<li><strong>Egress Processing:<\/strong> The modified packet exits <code>port1<\/code> toward the ISP gateway.<\/li>\n<li><strong>Return Packet Handling:<\/strong> When the web server replies to <code>203.0.113.10<\/code>, the FortiGate checks its active session table. Because stateful inspection tracks existing connections, return traffic matches the existing session automatically. The firewall bypasses policy lookup, restores the original destination IP (<code>192.0.2.50<\/code>), and forwards the packet out <code>port2<\/code>.<\/li>\n<\/ol>\n<h2>Verification<\/h2>\n<p>Confirm proper firewall operation by conducting checks on the local host and FortiGate CLI.<\/p>\n<h3>1. Check Routing Table from CLI<\/h3>\n<p>Execute the following command to verify the active IPv4 routing table in the kernel:<\/p>\n<pre><code>get router info routing-table all\n<\/code><\/pre>\n<p><em>Expected Output Excerpt:<\/em><\/p>\n<pre><code>S*      0.0.0.0\/0 [10\/0] via 203.0.113.1, port1\nC       192.0.2.0\/24 is directly connected, port2\nC       203.0.113.0\/24 is directly connected, port1\n<\/code><\/pre>\n<p>The routing table must show a candidate default route (marked with <code>S*<\/code>) pointing out your egress WAN interface.<\/p>\n<h3>2. Active Session Table Inspection<\/h3>\n<p>Send continuous outbound traffic from a LAN host (for example, pinging <code>198.51.100.25<\/code>). Then filter the session table on the FortiGate CLI using the client&#8217;s internal host address:<\/p>\n<pre><code>diagnose sys session filter saddr 192.0.2.50\ndiagnose sys session list\n<\/code><\/pre>\n<p><em>Expected Output Excerpt:<\/em><\/p>\n<pre><code>session info: proto=1 proto_state=01 duration=4 expire=56 timeout=60 flags=00000000 sockdef\/sockport=0\/0\n\tproto_statename=ICMP\n\tpkts\/bytes(req): 1\/84 pkts\/bytes(resp): 1\/84\n\tstate=may_dirty npu\n\tstatistic(total): packets=1 bytes=84 active1=1\n\tsrc\/dst: 192.0.2.50-&gt;198.51.100.25 id=1 dir=org act=noop\n\tsrc\/dst: 198.51.100.25-&gt;203.0.113.10 id=1 dir=reply act=snat\n\thook=post dir=org act=snat 203.0.113.10:61440\n\tmisc=0 policy_id=1 auth_info=0 vd=0\n<\/code><\/pre>\n<p>This session entry confirms that packet direction <code>org<\/code> (original) comes from <code>192.0.2.50<\/code>, while reply traffic hits <code>203.0.113.10<\/code> using policy ID 1 with active SNAT.<\/p>\n<h2>Troubleshooting<\/h2>\n<p>When outbound connectivity fails, follow a structured troubleshooting methodology: Link Layer -&gt; Routing -&gt; Firewall Policy -&gt; Session Execution.<\/p>\n<h3>Step-by-Step Flow Debugging<\/h3>\n<p>FortiOS contains a packet tracing tool that displays real-time flow decisions made by the kernel CPU. Run this command sequence to analyze drops or forwarding failures.<\/p>\n<p><em>CAUTION: In production environments with high traffic volume, always apply tight filters (such as specific host addresses) to avoid overwhelming CPU resources or flooding log consoles.<\/em><\/p>\n<pre><code>diagnose debug reset\ndiagnose debug flow filter saddr 192.0.2.50\ndiagnose debug flow show console enable\ndiagnose debug flow trace start 10\ndiagnose debug enable\n<\/code><\/pre>\n<p>Initiate traffic from the client host while observing the terminal output. A successful trace output appears as follows:<\/p>\n<pre><code>id=68586 trace_id=1 msg=\"vd-root:0 received a packet(proto=1, 192.0.2.50:1-&gt;198.51.100.25:8) from port2. type=8, code=0, id=1, seq=1.\"\nid=68586 trace_id=1 msg=\"allocate a new session-0000c12a, npu flag=00000000\"\nid=68586 trace_id=1 msg=\"find a route: flag=00000001 gw-203.0.113.1 via port1\"\nid=68586 trace_id=1 msg=\"Allowed by Policy-1:\"\nid=68586 trace_id=1 msg=\"SNAT 192.0.2.50-&gt;203.0.113.10:61440\"\n<\/code><\/pre>\n<h3>Interpreting Debug Trace Results<\/h3>\n<table>\n<thead>\n<tr>\n<th>Trace Message Symptom<\/th>\n<th>Probable Root Cause<\/th>\n<th>Corrective Action<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>Reverse path check fail<\/code><\/td>\n<td>Asymmetric routing or missing return route in table.<\/td>\n<td>Check default route configuration and verify subnet masks on local interfaces.<\/td>\n<\/tr>\n<tr>\n<td><code>No route to gateway... drop<\/code><\/td>\n<td>Missing static route or wrong outgoing interface assigned.<\/td>\n<td>Verify route destination and interface assignment under <code>Network &gt; Static Routes<\/code>.<\/td>\n<\/tr>\n<tr>\n<td><code>Denied by forward policy check<\/code><\/td>\n<td>Traffic matched implicit deny or policy options mismatch.<\/td>\n<td>Verify policy ordering, directional interfaces (srcintf\/dstintf), and address objects.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Safely Disable Debugging<\/h3>\n<p>Once diagnostics are complete, turn off debugging and clear operational trace filters immediately:<\/p>\n<pre><code>diagnose debug disable\ndiagnose debug reset\n<\/code><\/pre>\n<h2>Common Mistakes<\/h2>\n<ul>\n<li><strong>Forgetting to Enable NAT on Policy:<\/strong> Outbound packets leave the firewall containing private IP addresses (RFC 1918). Upstream ISP routers drop these packets because private ranges are non-routable on the public internet.<\/li>\n<li><strong>Reversing Source and Destination Interfaces:<\/strong> Setting the incoming interface as <code>port1<\/code> and outgoing interface as <code>port2<\/code> blocks internal outbound client access. Always establish rules relative to the traffic initiation path.<\/li>\n<li><strong>Missing Default Static Route:<\/strong> Configuring interfaces and security rules without a default static route leaves packets stranded at the firewall. The kernel drops packets missing destination FIB entries.<\/li>\n<li><strong>Assuming Central NAT Applies to Basic Policies:<\/strong> By default, FortiOS utilizes Policy NAT (NAT configured within the firewall rule). If Central NAT is manually enabled globally, port-level policy NAT parameters are hidden, requiring configuration under <code>Policy &amp; Objects &gt; Central SNAT<\/code>.<\/li>\n<li><strong>Misunderstanding Implicit Deny Rule 0:<\/strong> FortiGate appliances enforce an unseen, default policy rule at the bottom of the table blocking all unmatched connections. Every permitted flow requires explicit rule creation.<\/li>\n<\/ul>\n<h2>Production Considerations<\/h2>\n<p>While the configuration shown in this tutorial establishes connectivity, production deployments require extra hardening and structure:<\/p>\n<ul>\n<li><strong>Restrict Allowed Administrative Protocols:<\/strong> Never allow administrative management interfaces (<code>HTTP<\/code>, <code>HTTPS<\/code>, <code>SSH<\/code>) on untrusted public WAN interfaces. Restrict local administration strictly to secure LAN subnets or dedicated management interfaces.<\/li>\n<li><strong>Apply Security Profiles:<\/strong> Outbound policies should not rely purely on layer 4 firewalling. Apply security inspection profiles\u2014such as Antivirus, Web Filter, Application Control, and IPS\u2014to inspect allowed outbound flows for threats.<\/li>\n<li><strong>Restrict Allowed Services:<\/strong> Avoid using the generic <code>ALL<\/code> service object in enterprise production policies. Define strict, granular services (for example, port 80 <code>HTTP<\/code>, port 443 <code>HTTPS<\/code>, and port 53 <code>DNS<\/code>) to limit lateral threat vectors.<\/li>\n<li><strong>Configure Explicit IP Pools when Necessary:<\/strong> When managing multi-IP public blocks, switch from <strong>Use Outgoing Interface Address<\/strong> to designated <strong>IP Pools<\/strong> under <code>Policy &amp; Objects &gt; IP Pools<\/code> to maintain dedicated mapping policies for internal servers or specific departmental subnets.<\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>Configuring interfaces, routing, and stateful security rules represents the core foundation of enterprise networking on FortiGate firewalls. FortiOS relies on clear directional design: physical\/logical interfaces process traffic, the FIB handles route table selection, address objects identify traffic endpoints, and firewall policies evaluate permissions while applying translation rules.<\/p>\n<p>By mastering interface bindings, default static routes, address object generation, and policy NAT, you ensure safe edge connectivity across enterprise networks. Utilizing real-time verification tools like <code>get router info routing-table<\/code> and <code>diagnose debug flow<\/code> allows you to validate stateful session flows and resolve routing or policy blockages efficiently.<\/p>\n<h2>Related FortiGate Guides<\/h2>\n<ul>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-a-static-default-route-on-fortigate\/\">FortiGate Static Default Route Configuration<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-firewall-policy-configuration-with-a-real-life-example\/\">FortiGate Firewall Policy Configuration<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-source-nat-configuration-for-internet-access\/\">FortiGate Source NAT Configuration<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-sd-wan-configuration-for-dual-isp-failover-and-load-balancin\/\">FortiGate SD-WAN Configuration<\/a><\/li>\n<\/ul>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What interfaces are normally configured first on a FortiGate?<\/h3>\n<p>For a basic internet-edge deployment, configure the LAN and WAN interfaces first, then establish routing, address objects and the required firewall policy.<\/p>\n<h3>Why can a configured FortiGate interface still have no internet access?<\/h3>\n<p>An interface alone does not provide forwarding permission. Check the default route, firewall policy, NAT configuration and the client&#8217;s default gateway.<\/p>\n<h3>Should HTTPS and SSH be enabled on a FortiGate WAN interface?<\/h3>\n<p>Public management access should generally be disabled or tightly restricted. Use a dedicated management path or trusted source addresses whenever possible.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn FortiGate interfaces and firewall policies with a practical real-life example, step-by-step configuration, verification and troubleshooting.<\/p>","protected":false},"author":2,"featured_media":220,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[4],"tags":[28,29,41,42,44,43,30],"class_list":["post-221","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fortinet","tag-beginner","tag-firewall-tutorial","tag-fortigate","tag-fortigate-interfaces-and-firewall-policies","tag-fortinet","tag-fortios","tag-fundamentals"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>FortiGate Interfaces &amp; Firewall Policies: Step-by-Step<\/title>\n<meta name=\"description\" content=\"Configure FortiGate interfaces and firewall policies with a practical LAN-to-WAN example, including addressing, policy rules and verification.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Configure Interfaces and Firewall Policies on a FortiGate Firewall\" \/>\n<meta property=\"og:description\" content=\"Configure FortiGate interfaces and firewall policies with a practical LAN-to-WAN example, including addressing, policy rules and verification.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-03T17:51:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-13T23:11:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-configure-interfaces-and-firewall-policies-on-a-fortigate-firewall-featured-3.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"How to Configure Interfaces and Firewall Policies on a FortiGate Firewall\",\"datePublished\":\"2026-08-03T17:51:10+00:00\",\"dateModified\":\"2026-09-13T23:11:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/\"},\"wordCount\":1854,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/how-to-configure-interfaces-and-firewall-policies-on-a-fortigate-firewall-featured-3.png\",\"keywords\":[\"Beginner\",\"Firewall Tutorial\",\"FortiGate\",\"FortiGate interfaces and firewall policies\",\"Fortinet\",\"FortiOS\",\"Fundamentals\"],\"articleSection\":[\"FortiGate\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/\",\"name\":\"FortiGate Interfaces & Firewall Policies: Step-by-Step\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/how-to-configure-interfaces-and-firewall-policies-on-a-fortigate-firewall-featured-3.png\",\"datePublished\":\"2026-08-03T17:51:10+00:00\",\"dateModified\":\"2026-09-13T23:11:11+00:00\",\"description\":\"Configure FortiGate interfaces and firewall policies with a practical LAN-to-WAN example, including addressing, policy rules and verification.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/how-to-configure-interfaces-and-firewall-policies-on-a-fortigate-firewall-featured-3.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/how-to-configure-interfaces-and-firewall-policies-on-a-fortigate-firewall-featured-3.png\",\"width\":1200,\"height\":630,\"caption\":\"How to Configure Interfaces and Firewall Policies on a FortiGate Firewall\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Configure Interfaces and Firewall Policies on a FortiGate Firewall\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"FortiGate Interfaces & Firewall Policies: Step-by-Step","description":"Configure FortiGate interfaces and firewall policies with a practical LAN-to-WAN example, including addressing, policy rules and verification.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/","og_locale":"en_US","og_type":"article","og_title":"How to Configure Interfaces and Firewall Policies on a FortiGate Firewall","og_description":"Configure FortiGate interfaces and firewall policies with a practical LAN-to-WAN example, including addressing, policy rules and verification.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/","og_site_name":"NetworkFix","article_published_time":"2026-08-03T17:51:10+00:00","article_modified_time":"2026-09-13T23:11:11+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-configure-interfaces-and-firewall-policies-on-a-fortigate-firewall-featured-3.png","type":"image\/png"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"How to Configure Interfaces and Firewall Policies on a FortiGate Firewall","datePublished":"2026-08-03T17:51:10+00:00","dateModified":"2026-09-13T23:11:11+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/"},"wordCount":1854,"commentCount":0,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-configure-interfaces-and-firewall-policies-on-a-fortigate-firewall-featured-3.png","keywords":["Beginner","Firewall Tutorial","FortiGate","FortiGate interfaces and firewall policies","Fortinet","FortiOS","Fundamentals"],"articleSection":["FortiGate"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/","url":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/","name":"FortiGate Interfaces & Firewall Policies: Step-by-Step","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-configure-interfaces-and-firewall-policies-on-a-fortigate-firewall-featured-3.png","datePublished":"2026-08-03T17:51:10+00:00","dateModified":"2026-09-13T23:11:11+00:00","description":"Configure FortiGate interfaces and firewall policies with a practical LAN-to-WAN example, including addressing, policy rules and verification.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-configure-interfaces-and-firewall-policies-on-a-fortigate-firewall-featured-3.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/08\/how-to-configure-interfaces-and-firewall-policies-on-a-fortigate-firewall-featured-3.png","width":1200,"height":630,"caption":"How to Configure Interfaces and Firewall Policies on a FortiGate Firewall"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/configure-interfaces-and-firewall-policies-on-a-fortigate-firewall\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"How to Configure Interfaces and Firewall Policies on a FortiGate Firewall"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/221","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=221"}],"version-history":[{"count":2,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/221\/revisions"}],"predecessor-version":[{"id":1589,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/221\/revisions\/1589"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/220"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}