Skip to main content
NothingKai
New Member
October 24, 2016
Question

How to Block or Alow 1 device from WAN to local network.

  • October 24, 2016
  • 3 replies
  • 4126 views

Dear Guys,

 

I have a case, please give idead.

In picture, I wan creat policy for:

 

In the Chi nhanh 1

PC1 access to Server A, deny to Server B

PC2 access to Server B, deny to Server A

 

I try create device with MAC, and create Policy but not apply, please help.

 

3 replies

Nils
New Member
October 24, 2016

Hi,

You will not see the PC's mac-addresses on the Fortigate. You'll only see the mac-address of the nearest router.

So in this case you need to create the policy based on the PCs IP-addresses. 

Then you can achieve the scenario above.

andreadg88
New Member
October 24, 2016

Hi,

the routing happen at level3 of OSI stack.

Do you need to know the IP of source device to block it with firewall rule.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.