Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kadey
New Contributor II

Block gateway-sourced traffic...

I've created policies to restrict traffic to the internet sourced from a FortiGate 6.2 device itself, but they're not working. They're at the top of the policy list, and Deny in enabled.

 

Is this possible?

 

2 REPLIES 2
Dave_Hall
Honored Contributor

Hi Ken.

 

If you are trying to block incoming traffic from the Internet to your fgt, you will need to use a local-in-policy

 

Please note that ports used by the fgt are needed for certain services. This link explains what those ports are.  Is there a reason for wanting to block certain outgoing ports from the fgt itself?

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
kadey
New Contributor II

I'm just testing using Fabric Connector in policies, and just picked outbound traffic to test.

I can test with inbound as well, if I can use Fabric Connector objects in a local-in-policy.

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors