Skip to main content
k1rusty
New Member
November 26, 2023
Question

DMZ or IP Whitelisting

  • November 26, 2023
  • 4 replies
  • 2125 views

Hi!

I have an internal server and our vendor needs access to it on specific port. Its not ssh/RDP, some generic database port.

Normally any server with access from outside should be placed in DMZ. This is special case as we cannot move the server to DMZ. Do you think IP Whitelisting can provide the similar security.

Reverse proxy is also a solution but I not sure if it will create any performance issue or it will work fine.

So that leaves me to IP whitelisting in first place. Do you think it will provide enough security?

Thanks

4 replies

eowusu
Staff
Staff
November 26, 2023

Whitelisting just vendor's IP address as source in a firewall policy should be sufficient in providing security in the access of the internal server. Create a service port for the database port if it does not exist on the firewall. A vip object mapping your external IP(WAN) to the internal server and port forwarding enabled for the database port. Apply the VIP object in the firewall policy as destination in the firewall policy

AEK
SuperUser
SuperUser
November 26, 2023

Hello

In addition to eowusu's suggestion, you need to add two firewall policies.

  1. Fist one is to allow vendor's public IP to access your new VIP
  2. Second one, below the first policy, to deny any other traffic from WAN to your new VIP

You may also add security profiles (IPS, AV and so) to the first policy.

Doing that way should be quite secure.

AEK
mpeddalla
Staff
Staff
November 26, 2023

Hello  @k1rusty ,

 

Thank you for contacting the Fortinet Forum portal.

As explained by my colleague Eric and AEK can consider those processes please refer below article for procedure reference

1. create a custom port on the firewall  

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-create-custom-service-port-in-FortiGate/ta-p/283901Technical Tip: How to create custom service port i... - Fortinet Community

2. Add service by creating an external public ip VIP virtual IP for Natting to a private address.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-Virtual-IPs-to-configure-port-forwarding/ta-p/198195

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Virtual-IP-VIP-port-forwarding-configuration/ta-p/198143

 

-Additionally to protect the server from unwanted traffic on public IP as well, add deny policy other than specified services to that VIP and make sure to enable match-vip on firewall policy from CLI 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Firewall-does-not-block-incoming-WAN-to-LAN/ta-p/189641

 

Best regards,

Manasa.

 

If you feel the above steps helped to resolve the issue mark the reply as solved so that other customers can get it easily while searching on similar scenarios.

vbandha
Staff
Staff
November 26, 2023

@k1rusty 

Another option you can consider is using SSL VPN or IP Sec VPN. That would provide secure connection to the fortigate and not expose anything directly to internet. 

 

The option for whitelisting is also a good option, whichever is better suited for your environment. 

 

Regards, 

Varun

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!