Skip to main content
solidblueliquid
New Member
November 5, 2017
Question

Can you set a physical port to bypass the firewall rules?

  • November 5, 2017
  • 3 replies
  • 5633 views

I want to set one of my physical ports to bypass the security of the firewall. I currently sell the firewall as additional feature, so to accommodate this i'll like to set a port (say 14 for argument sake) to just allow all traffic in and out but still be monitored by the firewall.

 

Is that possible?

    3 replies

    emnoc
    New Member
    November 6, 2017

    You could apply a firewall policy with any/any  for  both  directions. This is not "TECHNICALLY" bypassing a firewall and no you can't BYPASS a port .

     

     A firewall is a firewall , and if your really  have tiers you should not place the  traffic thru a firewall/ The reason why, the  ANY/ANY approach mention above  eat resources  of a firewall and sessions.

     

     

    solidblueliquid
    New Member
    November 6, 2017

    I figured that'll be the answer, so better i just have a cable to a switch that's directly connected to the outside world?

    ede_pfau
    SuperUser
    SuperUser
    November 6, 2017

    No. Even if the policy allows ANY service to ANY destination, anytime, the firewall still provides routing and SNAT, and some protection if you apply UTM (AV, IPS). The latter might have an impact on the traffic - your call, this depends on your goal.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.