Skip to main content
gilbertojr
New Member
June 25, 2021
Question

Linux Repository

  • June 25, 2021
  • 1 reply
  • 4012 views

Hey, guys,

I have a question that I still can't resolve and I need help to resolve it. I need linux servers, regardless of operating system, only their proper repositories are allowed on the firewall. For example: a debian server needs to install the NTP service and I want to release for a period only the apt-get repositories so that the analyst can run this, the rest should be blocked. Currently, to perform any system update on linux or install new packages, I need to release all targets on ports 80 and 443. Is there a way to restrict this access from Linux machines on the firewall? I tried to look for something like IP Ranges used by each distribution or service in FortiGate Internet Services, but I couldn't find a simple way to do this. Has anyone been through this or had this need? I don't know if that would be the best way to act either. FortiOS is at version 6.2.7. Thank you all.

    1 reply

    abarushka
    Staff
    Staff
    June 6, 2022

    Hello,

     

    As far as I understand the goal is to allow traffic only towards certain linux repositories. In case I understand the scenario correctly you may consider to create firewall policy with the list of IP addresses of the servers or request new ISDB entry. Please find the form below:https://www.fortiguard.com/faq/isdb-contact

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!