Allow Pentester IP
I have FortiGate v7.2.5, where in the firewall can you whitelist the Pentester IP with the IPS Security Profile. Or is the best way to create a firewall policy to allow that traffic for the engagement?
I have FortiGate v7.2.5, where in the firewall can you whitelist the Pentester IP with the IPS Security Profile. Or is the best way to create a firewall policy to allow that traffic for the engagement?
Hi
It would depend on the contract between you and the pentester, if they have have to simulate any potential malicious user on the Internet you may not need to allow traffic for that source IP.
If you should need it, I would create a firewall policy and allow the traffic for that source specific IP. You can also decide to log the sessions on the specific firewall policy, but it would depend on what you have agreed with them. Be mindful anytime you have to allow any traffic on the WAN interface.
/!\ Make sure you enable/disable the allow firewall policy only when actually needed and once they finish, delete it.
Best regards,
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.