FortiAppSec Cloud
FortiAppSec Cloud delivers unified application security and performance with WAF, bot protection, GSLB, DDoS mitigation, threat analytics, and CDN.
Khidzir_MN
Staff
Staff
Article Id 251087
Description This article describes how to limit access to specific URLs from specific source addresses.
It may maybe necessary to preconfigure other respective Application setups and refer to the documentation at the end of this article for more information on onboarding the application.
Scope FortiAppSec Cloud.
Solution

It is necessary to limit access to specific URLs from specific source addresses.

 

For example:

There is a requirement to allow source IP 10.10.10.10 (using private IP as an example, the actual requirement may be using a Public IP) to access https://www.example.com/abc.

 

The Custom Rule feature may be used for the requirement.

 

  1. Go to ADVANCED APPLICATIONS -> Custom Rule.

It may be necessary to enable this module in the '+ ADD MODULES' menu, under ADVANCED APPLICATIONS -> Custom Rule.

 

  1. Select the '+ Create Rule' button on the right.

     

  2. For the Create Custom Rule, enter the respective information.
    For Name, specify the respective name to identify the rule, and for Operation, select Alert & Deny.

     

  3. Select the 'ADD FILTER' button on the right. For Filter Type, select Source IP and for IP/IP Range, input the respective source IP that needs to be allowed access. Enable the Reverse Matching option.

    Select the SAVE FILTER.

     
     

    createcustomrule.png

     

     

  4. Select the 'ADD FILTER' button again. For Filter Type, select URL and for URL Pattern, input the respective URL that needs to be allowed access. Select the SAVE FILTER.

     

    savecustomrule.png

     

     

  5. Select 'OK'.

     

  6. Select 'SAVE' on the Custom Rule page to apply the Custom Rule.

     

 

customrule.png

 

Related documents:

Application Onboarding

Custom Rule