Security policy to allow some services only for servers behind multiple wildcard urls?
Hi All,
I just worked around the fact that FortiOS (5.4.7 anyway) doesn't let you specify wildcard URLs for security policies. I get the issue of the possible performance hit, but wanted to check to see if people can suggest a better way to do this than what I've done.
Situation is a small subset of users, on their own vlan, that I need to allow to connect out to some specific external game servers. The two problems are:
1. There are a lot of game servers which are under multiple wildcard urls in multiple countries.
2. The connections need to allow a wide swath of tcp and udp ports, which I can't allow the use of to most external IPs.
So, I have a separate rule for these users, with a destination specified as the CIDR ranges owned by the company running the game servers, which allows both their normal service and all the tcp/udp ports needed for the game servers.
This works, but will break if the company buys a new set of IPs or outsources their servers.
Is there a cleaner way to do this with App Control or Web Filters? Note that the apps connecting to the game servers are not currently listed under App Control, and that I don't want to allow those ports to be used *anywhere* except to those game servers.
Thanks.
