Skip to main content
fingand
New Member
August 20, 2018
Question

IP/FQDN in a Service

  • August 20, 2018
  • 1 reply
  • 4784 views

Forgive my ignorance, but can someone explain the purpose of specifying an IP/FQDN in a FortiOS service?  If I create a service and specify the relevant ports (or port range) and also an IP/FQDN address will the service only apply if I’m accessing that particular IP/FQDN address.  If so, do I still need to specifically allow access to the destination IP address separately when I actually use the service in a policy?

 

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    August 20, 2018

    Your assumption is same as mine. The manual [http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-firewall-52/Firewall%20Objects/Configuring%20a%20new%20service.htm] says

    In the IP/FQDN field, an IP address or Fully Qualified Domain name can be entered if there is to be a specific destination for the service

    I think it's meant to be narrow down the service to only specific devices/IPs, like TCP 5000 only on 192.168.1.129, and TCP 5001 on 192.168.1.130, ... while in the destination field of the policy you specify 192.168.1.128/29.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.