Skip to main content
Trbonja
New Member
December 1, 2021
Question

URL in firewall rules

  • December 1, 2021
  • 5 replies
  • 7990 views

I'd like to create a firewall rules/policies based on URL not the IP.

Example:

- DMZ or LAN Server-one can access only abcdefg.com 

- DMZ or Server-two can access only gfedcba.com

Thank you,

T

5 replies

Harbib
Staff
Staff
December 1, 2021

Hello Trbonja,

 

You will have to create an FQDN address and apply that address in your firewall policy.

https://docs.fortinet.com/document/fortigate/6.2.0/new-features/329154/support-for-wildcard-fqdn-addresses-in-firewall-policy-6-2-2

 

GoodLuck.

Trbonja
TrbonjaAuthor
New Member
December 1, 2021

Thank you!

 

T

pavankr5
Staff
Staff
August 1, 2023

Hello @Trbonja,

 

To create firewall rules or policies based on URLs rather than IP addresses. You need to generate a  FQDN address and then incorporate it into your firewall policy.

https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/217973/using-wildcard-fqdn-addresses-in-firewall-policies

Thanks

Pavan

Contributor III
August 1, 2023

Hi @Trbonja,

To allow the traffic you need to create a Firewall policy.

Within the Firewall policy you can create FQDN object with specific URL as per your requirement.

Ensure do define right source and destination  in the order of preference for the policy hits.

This should work.

 

Thanks,

Kruthi

 

mgoswami
Staff
Staff
August 1, 2023

Hi,

 

For creating policies for destination URLS, you may create FQDN and use the FQDN on the policy. You may refer to this link for the asme:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-wildcard-FQDN/ta-p/196118

BR,

Manosh

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!