Deny IP ADDRESS over VPN
Hello,
I have 3 fortigates connected with vpn.
FGT_A =========== FGT_B ============ FGT_c
Lan FGTA: 192.168.1.0/24
Lan FGTB: 192.168.2.0/24
Lan FGTC: 192.168.3.0/24
The internal network of the fortigate A acesses the internal network of the fortigate C through the fortigate B, however, I can not only block an ip in the fortigate C. I want to completely block ip 192.168.1.10, it should not access the 192.168.3.0/24 network. I create the denying policy on fortigate C, however in the diag sniffer it still traffics by ip-proto-4, how do I only block one ip?
192.168.1.10 -> 192.168.3.200: ip-proto-4 52
192.168.1.10 -> 192.168.3.200: ip-proto-4 88
192.168.1.10 -> 192.168.3.200: ip-proto-4 52
192.168.1.10 -> 192.168.3.200: ip-proto-4 88
192.168.1.10 -> 192.168.3.200: ip-proto-4 52
192.168.1.10 -> 192.168.3.200: ip-proto-4 88
