How can I make my public facing interface secure on Fortigate?
We have a CCTV network which is on a separate vlan. There’s a server with static IP address that is on the same vlan and has the software that manages the cameras etc. This CCTV vendor has a mobile app too, which lets you connect remotely to this server via a public IP address which we got from our ISP. Owner and some managers want to view the live feed from the CCTV cameras from home on their phones if needed. I have mapped one of our public IPs to the server’s private IP address via Virtual IPs (NAT) in Fortigate. It works as intended but I am concerned about its security.
In the policy I have Web Access (HTTPS, HTTP, DNS) services enabled and have enabled Security Profiles for this policy. I can set specific sources (IP addresses) to be able to connect but then cell phone IP addresses (from phone carriers) change because they are not static. Currently the source is set to “all” which concerns me.
Is it not a safe approach from cybersecurity perspective?
