Skip to main content
Tutek_OLD
New Member
March 6, 2021
Question

Bind port to ip address object in firewall policy

  • March 6, 2021
  • 1 reply
  • 2515 views

Hi,

I need to allow access to couple of my servers on vlan, but every server should be accessible only on its own service port, let's say:

server 10.1.1.1 only access on port 443

server 10.1.1.2 port 1433

server 10.1.1.3 port 3389

if I add these servers IP as address objects, with each service ports then these service ports will be shared among all servers so then client can access my 10.1.1.1 server over RDP 3389, right?

Is any way to simply create one ipv4 policy instead many separate policies with one ip and one service port for this ip?

thanks

    1 reply

    ede_pfau
    SuperUser
    SuperUser
    March 7, 2021

    I'm afraid there isn't.

    You could employ scripting if the number of policies needed is excessive.

     

    The only other way to obtain this might be to use VIPs instead of destination addresses. In/out address would be the same, in-port/out-port identical but only the allowed port mentioned. If there is no other, more general policy towards this server you'd block unwanted traffic.

    Put all VIPs into one VIP group, and into one policy.

     

    But I doubt this way would be less work or more transparent/comprehensible.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!