Skip to main content
HS08
Visitor III
August 26, 2025
Question

VPN Dialup Access List

  • August 26, 2025
  • 1 reply
  • 906 views

How we can create access list to limit which ip address can be connected to the vpn dialup?

1 reply

Toshi_Esumi
SuperUser
SuperUser
August 26, 2025

Use local-in policy. Service "IKE" covers both UDP 500 and 4500.
https://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/363127/local-in-policy

 

<edit> Almost forgot to mention, local-in policy config in GUI started with 7.6.x. If you're running 7.4.x or below, you need to use CLI. </edit>

Toshi

HS08
HS08Author
Visitor III
August 26, 2025

i try to make local policy but there is no tunnel dial-up interface and even no interface of my internet (port1)

Toshi_Esumi
SuperUser
SuperUser
August 26, 2025

No. The local-in policy works outside of the tunnel. You just need to apply it to the physical incoming interface, port1. Are you using 7.6 GUI or CLI?
If you're using SD-WAN, you might need to use "virtual-wan-link" zone name instead.

Toshi