- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate with public IP
Hi guys, a need assistance with a FortiGate that currently have access with a public IP and I don know how to disable this to only access with my VPN.
I'm new about Fortinet so there are some things that I don't know.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In GUI under Network->Interfaces, open and enter into Edit mode of the interface your public IP is configured, likely one of wan interfaces. In Administrative Access section, HTTPS and/or HTTP must be "checked". Just uncheck them. That would disable it. Make sure you do this while you're connected via VPN.
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Toshi
If I do this, it will mean that I will access with VLAN IP I previously configured?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The change you would make is to just disable HTTPS/HTTP access to the wan interface with its public interface IP. It wouldn't affect any other interfaces including the internal interfaces you can reach over a VPN, and which I assume you've set up your admin access to with its interface (private) IP. You will keep using it without any additional change.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Toshi,
I tried what you said but it doesn't work, also I have a VLAN with a private IP but still doesn't work, in the VLAN I enable HTTP/HTTPS.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm assuming the VLAN interface is allowed for PING and you can ping it from internal device. Also assuming the VLAN subnet has been made reachable over VPN. Can you ping it over the VPN? If not you need to troubleshoot the reachability problem first.
Toshi
