Skip to main content
Hams
Explorer
November 13, 2023
Solved

Allow Pentester IP

  • November 13, 2023
  • 2 replies
  • 2295 views

I have FortiGate v7.2.5, where in the firewall can you whitelist the Pentester IP with the IPS Security Profile. Or is the best way to create a firewall policy to allow that traffic for the engagement?

Best answer by fricci_FTNT

Hi @Hams ,

 

It would depend on the contract between you and the pentester, if they have have to simulate any potential malicious user on the Internet you may not need to allow traffic for that source IP. 
If you should need it, I would create a firewall policy and allow the traffic for that source specific IP. You can also decide to log the sessions on the specific firewall policy, but it would depend on what you have agreed with them. Be mindful anytime you have to allow any traffic on the WAN interface.

/!\ Make sure you enable/disable the allow firewall policy only when actually needed and once they finish, delete it.

 

Best regards,

2 replies

fricci_FTNT
Staff
Staff
November 13, 2023

Hi @Hams ,

 

It would depend on the contract between you and the pentester, if they have have to simulate any potential malicious user on the Internet you may not need to allow traffic for that source IP. 
If you should need it, I would create a firewall policy and allow the traffic for that source specific IP. You can also decide to log the sessions on the specific firewall policy, but it would depend on what you have agreed with them. Be mindful anytime you have to allow any traffic on the WAN interface.

/!\ Make sure you enable/disable the allow firewall policy only when actually needed and once they finish, delete it.

 

Best regards,

Toshi_Esumi
SuperUser
SuperUser
November 13, 2023

If internal devices, like a prove device the tester installed, need to interact with the outside server, and they told you that traffic needs to be exempt from IPS, you need to create a new policy specifically to allow the internal device(s) to the external IP without the IPS profile.
But if it's for the outside IP toward the internal devices with VIPs they need to scan, I wouldn't exepmt it. You should ask about the detail what they're expecting.

 

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!