Skip to main content
solidblueliquid
New Member
December 24, 2017
Solved

Newbe! Help required to restrict 1 IP address

  • December 24, 2017
  • 8 replies
  • 12492 views

Hi Everyone,

 

I have a fortigate 100D and need help configuring a rule correctly. I have 1 IP address that is the root IP of a server (its a Xenserver). I want to restrict access to this server to only a subnet of IP addresses and 1 specific one, for example;

 

1.1.1.1/24

1.1.1.1

 

Nothing else should be able to talk to that device. I'm on firmware v5.6.0, currently in my addresses I have a group called Servers which covers the IP addresses that are assigned to all the potential servers, I'm assuming if I split this into, Xenserver and Servers then i can lock down the Xenserver address specifically?

 

Any help would be appreciated, i don't want to do this blind as the server is an hour away by car and would rather not have to go there everytime i wanted to do anything

 

Thanks

Best answer by rwpatterson

In the Fortigate firewall world, the device can only be reached if there is a policy in place, so if you only create a policy for that one IP pair, then the others will automatically be protected. Hope that answers your query. One policy from 42.52.57.23 to 22.52.123.108 and you should be fine.

8 replies

sw2090
SuperUser
SuperUser
January 2, 2018

hiho,

 

at first: in your example your specific ip is a part of the subnet. 

1.1.1.1/24 would anyhows have 1.1.1.1 as network address so that would not be a host :D

1.1.1.1/24 would additionaly not be a vaild subnet hence it would not have 255 addresses.

 

So let me assume you meant 1.1.1.0/24 and 1.1.1.1.

Then 1.1.1.1 would be a valid host and is part of 1.1.1.0/24.

 

So if you want to restrict the server to 1.1.1.0/24 you have to create an object for this subnet.

Then make a policy with the following:

 

Source-Address is you subnet 1.1.1.0/24 (referenced by the object you created in the step before)

Source-Interface will be the interface of the fortigate where the traffic of 1.1.1.0/24 comes in.

Destination-Address will bei the IP of your server (also referenced by an object).

Destination-Interface will bei the interface via wich your server is to be reached.

 

Since FortiOS 5.4 you are btw able to create Objects from within the selection menue!

 

If there are more Policies that grant access to the subnet the server is in or the server itself you have to take care of the order of the policies. FortiOS will stop applying policies one one was matched!

 

So if you already have a policy that denies access to the server from everywhere than all policies that grant access have to come before it! 

 

So you need:

 

- Policy that allows traffic from 1.1.1.0/24 to server

- Policy that allows traffic from specific ip to server (that is not in 1.1.1.0/24)

- Policy that denies all access to server

 

if your specific ip is in 1.1.1.0/24 the first policy will already match so the second and third will no more be aplied.

 

solidblueliquid
New Member
January 2, 2018

Sorry that was a bad example... i was using 1.1.1.1 as blank address rather than a real one.

 

I see where your example goes, and if I wanted to allow access to the server from another address I would just have to add another ALLOW in the policy?

sw2090
SuperUser
SuperUser
January 2, 2018

Probably this will do but I never did that way. 

I prefer using an own policy for each host or net because on the policy overwie you have a better overview then.

Because on our main Fortigate I have 32 ipsec tunnels that have policies that give me access to specific subnets over each one of them so this escalates rather quickly ;)

 

But yes FortiOS supports adding more objects as source or destination on one policy. So you could do this.

You could also group objects and then use the group as source or destination. In this case you just need to add a new host or subnet to that group and not even touch any policy :)

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!