Skip to main content
lostboy10
Explorer II
January 30, 2025
Question

Limit Access to an internal website in Fortigate

  • January 30, 2025
  • 6 replies
  • 1259 views

I have an internal application to which i want to limit the sessions from a particular source IP.. i.e. an IP should not be able to stablish more than 10 sessions to that application..i understand i can create a threshold for this in IPv4 DOS Policy but the source IP is part of a header.. is it possible to limit sessions based on the source IP contained in the header ? 

6 replies

AEK
SuperUser
SuperUser
January 30, 2025

I don't know such feature on FortiGate. But probably it exists on FortiWeb.

AEK
lostboy10
lostboy10Author
Explorer II
January 31, 2025

i also have a fortiweb behing the fortigate.. is it possible to do so in fortiweb ?

 

AEK
SuperUser
SuperUser
January 31, 2025

After double-check yes you can do it with FortiWeb.

Here's a video from video.fortinet.com that explains how FWB can read the IP from the header (X-Forwarded-For) and block it if it is from specific GeoIP.

The trick is to enable "Use X-Header to identify original client's IP" in your X-Forwarded-For rule.

https://video.fortinet.com/latest/fortiweb-how-to-use-the-x-forwarded-for-header-to-identify-real-client-ips

Hope it helps.

AEK
dingjerry_FTNT
Staff
Staff
January 30, 2025

Hi @lostboy10 ,

 

I don't think that FortiGate can do it. At least, I am not aware of it.

Dhruvin_patel
Staff
Staff
January 30, 2025

Hello,

 

To limit sessions to an internal website based on the source IP contained in the header in FortiGate, you can utilize the Traffic Shaper feature. Within the Traffic Shaper policy settings, set the maximum concurrent connections to 10 for the source IP you want to limit.

 

Reference Document: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Limit-connections-to-a-specific-destination-IP/ta-p/244968

 

Regards!

lostboy10
lostboy10Author
Explorer II
January 31, 2025

thx for the link.. the source ip in the traffic shaper policy will be of the source ip visible in the header or the one which shows in traffic logs ? 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!