Skip to main content
sasad
Visitor III
February 8, 2024
Solved

Access through IP should not be allowed for Firewall management only FQDN allowed.

  • February 8, 2024
  • 11 replies
  • 3891 views

Dear

 

We have Fortigate FG200E firewall, we need to access the Firewall through FQDN for that we have added the A records in our local and public DNS.

 

But now we need to stop the access direct from public IP, and the administrators must use the FQDN to access the Firewall management page.

 

Can anyone please help that how can I achieve this?

11 replies

AEK
SuperUser
SuperUser
February 8, 2024

Hello Sasad

Since this is a field of http request, as far as I know this can be done if you have a WAF between clients and FG.

On the other hand may I ask why such requirement?

AEK
sasad
sasadAuthor
Visitor III
February 8, 2024

We need it as we have multiple sites and our admins access them frequently and our certificate is on FQDN this is not support IP address, so the communication will not be encrypted in this case.

AEK
SuperUser
SuperUser
February 8, 2024

You still can issue one single certificate for both FQDN and IP address, so your communication will be secure if you use either FQDN or IP.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!