Skip to main content
freber
New Member
September 11, 2021
Solved

Block internal IP from VPN

  • September 11, 2021
  • 3 replies
  • 4225 views

Hi all!

 

We have a working SSL VPN that lets outside users access our internal LAN. But I want to restrict access to specific local addresse. Ie I dont want any VPN users to access 192.168.0.20.

How do I block a specific local IP?

    Best answer by Toshi_Esumi

    You must have a ssl.root->[internal_interface] policy allowing all. Just put another policy blocking the host .20 right above the existing policy.

    3 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    September 11, 2021

    You must have a ssl.root->[internal_interface] policy allowing all. Just put another policy blocking the host .20 right above the existing policy.

    Yurisk
    SuperUser
    SuperUser
    September 12, 2021

    That's the beauty of Interface/Route-based VPNs - you treat your VPN users as located somewhere on the Internet and connected to your LANs via ssl.root interface, as the consequence, you allow/block this traffic in security policy  as you do with any traffic passing the firewall from interface to interface.

     

    yurisk.info - all things Fortinet blog, no ads
    freber
    freberAuthor
    New Member
    September 12, 2021

    I have a deny policy now which has destination .20 and when its not in effect the users can reach everything and when it is applied they cant connect at all.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.