Skip to main content
mickgaffney
New Member
March 8, 2017
Question

FortiGuard 100D

  • March 8, 2017
  • 1 reply
  • 4021 views

All I am new to fortinet, however I want to block access to the admim web gui from all external ips addresses to my LAN,

 

Any idea on how this is completed?

    1 reply

    ede_pfau
    SuperUser
    SuperUser
    March 9, 2017

    Hi,

     

    and welcome to the forums.

     

    Admin access is governed by the 'Trusted Hosts' setting in each admin user setup. Though it's a whitelist: you can specify the subnet from which you allow access but you cannot specify which subnets you disallow.

    As long as any of the 3 subnet fields contains '0.0.0.0/0' access from anywhere is granted.

     

    Enjoy!

    mickgaffney
    New Member
    March 9, 2017

    Is there not a way to totally block access to the web gui from the INternet, othere than updating admin accounts to remove the 0.0.0.0 address range?

    ede_pfau
    SuperUser
    SuperUser
    March 9, 2017

    Ah yes, if you want to totally disable admin access for the WAN interface, go into the interface settings and un-check all 'Allow access' boxes (default: HTTPS, SSH, ping).

     

    You might think twice about disabling ping. It isn't bad in itself but can help a ton.