FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
hhasny
Staff
Staff
Article Id 242872
Description This article describes how to limit access to the FortiGate dedicated management interface using trust-ip.
Scope FortiGate.
Solution

When 'dedicated-to management' is configured, it is possible to limit the access using trust-ip. This is similar to what is available with trusted-host under 'system admin'.

 

Below is the interface port10 that has been set 'dedicated-to management'.

 

hhasny_0-1673628851593.png

 

In this example, only 10.1.1.101/32 is allowed access to Fortigate management through this port10 interface. Other IPs would be denied.

 

The logs below show denied IPs:

 hhasny_3-1673629136920.png

 

hhasny_2-1673629014200.png

 

It is possible to add up to 3 IPv4 and 3 IPv6 trust-ips.

 

Reference:

http://docs.fortinet.com/document/fortigate/6.2.12/cli-reference/8620/config-system-interface

Contributors