Dear All,
I'm new to Fortigate and new to the forum. Anyway, I have a problem configuring policies for blocking unwanted access from some external/malicious IP addresses.
Here's what I did.
config firewall policy
edit 4
set uuid 10be693f-5610-45a9-bebc-c27bd394177f
set srcintf "any"
set dstintf "any"
set srcaddr "group-blacklist"
set dstaddr "all"
set schedule "always"
set service "ALL"
set logtraffic all
next
end
I have put the policy on top of the list. However, when I tried accessing my FW from blocked IP address, it still can go through and no traffic were recorded to the policy log. Am I missing any steps or is there any other way? Thank you guys.
Fortigate 60D
v5.2.6,build711 (GA)
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
This is not about VIPs but administrative access to the FGT, right?
You can do 2 different things:
1- only allow certain public IPs to access the FGT (white listing) - go to System>Admin>myadmin>TrustedHosts
2- create a local-in policy which uses a predefined custom address group as source address(es). Local-in policies are only managed in the CLI.
Dear friend ,
there is simple solution to block ip to access WAN from outside just go to policy and Object and create address put you geographical address .
and put at source of policy which is access you wan from out .
It will block all world accept you region and if know the exactly the public IP address of you device to access the system then do same procedure an put them in to source of wan policy only that publi IP will able to access that device .
thank you
with regards
Sunil Panchal
IT Security Engineer
T: +965-2244 5419/391 | M: +965-6969 1505
F: +965-2246 7519 | E: sunil@topwnet.com
PSave a tree! Don't print this e-mail unless it's really necessary.
I have the same issue. Can anyone out there help>??
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.