Skip to main content
J_McGe
Visitor III
March 13, 2025
Solved

Policy creation to allow 2 options, log all other attempts

  • March 13, 2025
  • 1 reply
  • 609 views

I have a Fortigate F100 with rules in place for the management address of my company's UPS. One policy allows SMTP traffic from that address to our mil server. The other allows DNS traffic from that address, nothing else. I'd like to log any other traffic from the address in question that doesn't match either of these two rules; what's the simplest way to configure such a policy? Just clone the 'UPS Management Address to DNS' rule, set it to DENY instead of ACCEPT, choose every service other than DNS, and hit the log option?

Best answer by AEK

Create a rule under those two rules, set the client IP as source, service = ALL, and action = Deny.

1 reply

AEK
SuperUser
AEKAnswer
SuperUser
March 13, 2025

Create a rule under those two rules, set the client IP as source, service = ALL, and action = Deny.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!