Skip to main content
azaan
New Member
October 10, 2017
Question

Block access to SNMP service from internet

  • October 10, 2017
  • 4 replies
  • 7325 views

Hi, 

 

Can anyone guide me how to block SNMP service from internet on fortinet. 

 

Thanks 

 

    4 replies

    emnoc
    New Member
    October 10, 2017

    We are assuming snmp access to the FGT? Use the snmp host entries and enable SNMP allowaccess  only on the  interface(s) that you need.

     

    e.g cli

     

     config hosts                 edit 1                     set ip 12.130.11.0 255.255.255.0                 next                 edit 2                     set ip 207.18.1.8 255.255.255.255                 next

                    edit 3                     set ip 207.19.1.89 255.255.255.255                 next             end

    azaan
    azaanAuthor
    New Member
    October 10, 2017

    Hi, 

     

    Thanks for your reply, 

     

    Can we block ports like TC/UDP - 161, 162 for any incoming traffic from internet. or is there any other way to do this. 

     

     

    oheigl
    New Member
    October 11, 2017

    Like emnoc said: Just disable the SNMP in the allow access settings of your WAN interface. This way the FortiGate doesn't listen on the SNMP ports anymore for this interface

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!