Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Huxleyarelq
New Contributor

Azure VMs behind FortiClient

I have azure networking backend hosting azure subnet with my DC and computers subnet x.x.x.x/16 and then I have another subnet in azure hosting my fortigate VM y.y.y.y/22. On my fortigate VM I have the local LAN z.z.z.z/26. I have configured the fortigate with FortiClient and would like the DC and computers in Azure to only be reachable through connecting to the FortiClient.  

5 REPLIES 5
Stephen_G
Moderator
Moderator

Hello Huxleyarelq,

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Thanks,

Stephen - Fortinet Community Team
Stephen_G
Moderator
Moderator

Hi Huxleyarelq,


We are still trying to get you an answer or help. We will respond to you as soon as possible.

 

Kind regards,

Stephen - Fortinet Community Team
Stephen_G
Moderator
Moderator

Hi Huxleyarelq,

 

I apologise for the delays on our end. While I talk to more of our team members: @AEK , is this an area you're familiar with?

 

Kind regards,

Stephen - Fortinet Community Team
AEK
SuperUser
SuperUser

Hi @Huxleyarelq 

  • Can your FortiGate reach your Azure DC x.x.x.x/16
  • Is this DC subnet x.x.x.x/16 public IP? Is it reachable from any host from the Internet?
  • Is the subnet x.x.x.x/16 behind some firewall?
AEK
AEK
vbandha
Staff
Staff

Hi @Huxleyarelq 

Is the access to Azure subnet with DC and computers  (x.x.x.x/16) being controlled by fortigate?
If the traffic can go directly to this subnet without passing through fortigate, then fortigate can't restrict the access.

If the traffic has to go through fortigate to reach these subnets then you can create a firewall policy rule to limit access to these subnets.

You would create a policy from VPN to this subnet.

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/656084/firewall-policy


From your description, it seems that the x.x.x.x/16 is not behind fortigate so you may need to configure appropriate routing on azure so the access to this subnet passes through fortigate.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors