Skip to main content
RJ45
Visitor III
August 13, 2024
Solved

Creating a "Deny but Poke Holes" Set of Policies

  • August 13, 2024
  • 1 reply
  • 904 views

I own a Fortigate 60F. I'm a contract worker, operating from home. The company I'm working with demands that I'm behind a firewall which is set to reject ALL TRAFFIC except only needed services and web sites, just so there is maximum rejection of anything from the outside. I have also purchased the package which has IPS so that I'm in compliance, as they are most concerned with asset egress. It's Draconian, I know.

 

My question is, what is the most efficient way to configure for this, using the fewest policies? To simplify, let's assume I need the following 3 "essential" things:

 

1. The company's Okta site, we'll call it "company.okta.com"

2. Ability to sync with the Dropbox service

3. An Apple file server, let's call it "afp://server.company.com

 

For example, I can't tell whether using the Web Filtering is better than an individual policies which specify FQDNs, etc.

Is it best to create a policy just specifying Dropbox's "Internet Service" services? Or some other method?

Thank you

 

 

 

Best answer by hrahuman_FTNT

Hi,

 

For your requirement , use the following:

 

1. The company's Okta site, we'll call it "company.okta.com" >>>> Use FQDN

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-a-wildcard-FQDN/ta-p/196118

2. Ability to sync with the Dropbox service >>>  For public cloud services, it is better to use Internet service instead of FQDN.

https://community.fortinet.com/t5/FortiGate/Technical-TIp-Use-Internet-Service-Database-vs-FQDN/ta-p/270814

 

3. An Apple file server, let's call it "afp://server.company.com  >>>> Use FQDN with service.

 

 

 

1 reply

hrahuman_FTNT
Staff & Editor
Staff & Editor
August 13, 2024

Hi,

 

For your requirement , use the following:

 

1. The company's Okta site, we'll call it "company.okta.com" >>>> Use FQDN

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-a-wildcard-FQDN/ta-p/196118

2. Ability to sync with the Dropbox service >>>  For public cloud services, it is better to use Internet service instead of FQDN.

https://community.fortinet.com/t5/FortiGate/Technical-TIp-Use-Internet-Service-Database-vs-FQDN/ta-p/270814

 

3. An Apple file server, let's call it "afp://server.company.com  >>>> Use FQDN with service.