Created on
01-27-2025
10:17 PM
Edited on
01-30-2025
12:59 AM
By
Jean-Philippe_P
Description | This article describes VIP access allowed for internal users only and blocked for external users. |
Scope | FortiGate. |
Solution |
Topology: FGT1----------->FGT2(10.5.61.164)------------->PC(20.20.20.2).
In the above scenario, the PC takes access to FGT1 using the Public IP of FGT2 10.5.61.164 on port 5444.
Configuration on FGT2 is done as below:
graviton-kvm39 # config firewall vip graviton-kvm39 (vip) # edit "FW-Access" graviton-kvm39 (FW-Access) # show
graviton-kvm39 # config firewall policy graviton-kvm39 (policy) # edit "2" graviton-kvm39 (2) # show
Note: Make sure to enable the source interface in the VIP configuration.
If multiple VIPs are there with different mapped IPs, and different mapped Interfaces, use 'srcintf-filter' to map the VIP to a specific interface as below.
graviton-kvm39 (FW-Access) # set srcintf-filter port4 graviton-kvm39 (FW-Access) # end
Try to access FGT1 with the Public IP of FGT2 from the PC.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.