Skip to main content
t_krawaczynski
New Member
July 21, 2022
Solved

Internet block but not all

  • July 21, 2022
  • 2 replies
  • 7502 views

Hello everyone, I have a problem with internet blocking on production computers. If I disable Internet access for this network, I have a problem with windows / linux updates and additionally after entering my server in the local network, my site after https is dangerous because the computer cannot connect to verify the certificate. Any ideas?

Best answer by larsbollas

Hi @t_krawaczynski,

You need to create a new IPv4 policy to allow certain types of traffic like windows and linux update to your network. Then, you have to move that policy on the top of the existing policy which blocks the internet connection.

For the server, you might need to import the server's SSL certificate into the fortigate:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-import-SSL-certificate-as-a-local/ta-p/192766

Regards,
Lars Bollas
 

2 replies

larsbollas
Staff
Staff
July 21, 2022

Hi,

I just want to confirm, you want to block internet access in your network, but you still want the updates to come through for windows and linux?

t_krawaczynski
New Member
July 21, 2022

Yes, and my local server has an SSL certificate to connect to https. The production computer must also have access to the certification organization

larsbollas
Staff
Staff
July 21, 2022

Hi @t_krawaczynski,

You need to create a new IPv4 policy to allow certain types of traffic like windows and linux update to your network. Then, you have to move that policy on the top of the existing policy which blocks the internet connection.

For the server, you might need to import the server's SSL certificate into the fortigate:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-import-SSL-certificate-as-a-local/ta-p/192766

Regards,
Lars Bollas
 

t_krawaczynski
New Member
July 21, 2022

Thank you very much, I already know how to do it