Using Fortigate to Protect Web Server Hosting VDI
Hoping for some real world use cases for the following setup where we are protecting a hardened front end web server that sort of proxies connections into our Horizon VDI environment..
We currently have a VIP on TCP.443 that publishes the previously mentioned web server into our VDI environment (Horizon) and we're currently restricting traffic on that corresponding rule by allowing only IP's in the United States and only the users WAN IP address given to them by their ISP but in some cases we're allowing some /16's that would encompass some of the more widely used ISP's within our footprint.
We also use FortiAuthenticator so every VDI user must participate with MFA which is typically done off of FortiToken Mobile App and we run AV Scanning/IPS/etc. on that same rule, but the management of it all is becoming too cumbersome considering we'll have some 500 virtual desktops by the end of 2022 and even more into the coming years. What are some other viable way to restrict the traffic hitting this VIP/Rule?
We have talked about just opening with some GEO-Fencing to only IP's based in the United States and then rely on the web servers hardened configuration to protect us but are just not sure what everyone else is doing out there or what is the "acceptable standard" for this type of setup. We are also a little confused about MAC verification since every time you leave a local switch your MAC gets stripped away but restricting via MAC address (along with everything else) would be great.
Any insights that you may have would be absolutely great and muchly appreciated...
Dave
