What is/are your way(s) to block the target from accessing your servers?
Hello,
I am looking for "the best way" to block an Ip address from the internet to access my servers.
One funny man just tells me to
1. create a loopback interface on Fortigate
2. create an object group, enable the "Static route configuration", and add those BlackList IP addresses to that object group
3. Add a static route, Dst set to the object group, Route interface: The loopback one
So, the "return traffic" is eliminated.
Well, I then find a KB from Fortinet and just have a Firewall policy with "match-vip enable" to block the target.
Technical Tip: Firewall does not block incoming (W... - Fortinet Community
So, what is/are the difference(s) between both methods?
And, are there even benefits if we are using the Funny guy's solution? Like CPU loading / Memory loading ... anything is better than the match-vip.
