Skip to main content
yeowkm99
New Member
October 18, 2024
Question

Restrict incoming traffic to email archive server

  • October 18, 2024
  • 2 replies
  • 1020 views

We want to restrict incoming traffic from external to our email archive server.

We are currently using M365 email service.

currently we have on policy from WAN to LAN, all to archive server, services - https, ssh, ntp, dns, tcp8000.

how can we restrict the incoming traffic ?

2 replies

rahul_p1
Staff
Staff
October 18, 2024

Hi,

Please create a firewall policy from wan to lan to deny traffic on the basis of ISDB or server IP:- 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Creating-a-Deny-Policy-using-Internet-Service/ta-p/231076

 

yeowkm99
yeowkm99Author
New Member
October 18, 2024

we want to allow only microsoft services but it seems if I use Internet service group, some services are for destination only and cannot be used as source