I have azure networking backend hosting azure subnet with my DC and computers subnet x.x.x.x/16 and then I have another subnet in azure hosting my fortigate VM y.y.y.y/22. On my fortigate VM I have the local LAN z.z.z.z/26. I have configured the fortigate with FortiClient and would like the DC and computers in Azure to only be reachable through connecting to the FortiClient.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Huxleyarelq,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hi Huxleyarelq,
We are still trying to get you an answer or help. We will respond to you as soon as possible.
Kind regards,
Hi Huxleyarelq,
I apologise for the delays on our end. While I talk to more of our team members: @AEK , is this an area you're familiar with?
Kind regards,
Hi @Huxleyarelq
Hi @Huxleyarelq
Is the access to Azure subnet with DC and computers (x.x.x.x/16) being controlled by fortigate?
If the traffic can go directly to this subnet without passing through fortigate, then fortigate can't restrict the access.
If the traffic has to go through fortigate to reach these subnets then you can create a firewall policy rule to limit access to these subnets.
You would create a policy from VPN to this subnet.
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/656084/firewall-policy
From your description, it seems that the x.x.x.x/16 is not behind fortigate so you may need to configure appropriate routing on azure so the access to this subnet passes through fortigate.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1547 | |
1031 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.