Hi!
I have an internal server and our vendor needs access to it on specific port. Its not ssh/RDP, some generic database port.
Normally any server with access from outside should be placed in DMZ. This is special case as we cannot move the server to DMZ. Do you think IP Whitelisting can provide the similar security.
Reverse proxy is also a solution but I not sure if it will create any performance issue or it will work fine.
So that leaves me to IP whitelisting in first place. Do you think it will provide enough security?
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Whitelisting just vendor's IP address as source in a firewall policy should be sufficient in providing security in the access of the internal server. Create a service port for the database port if it does not exist on the firewall. A vip object mapping your external IP(WAN) to the internal server and port forwarding enabled for the database port. Apply the VIP object in the firewall policy as destination in the firewall policy
Hello
In addition to eowusu's suggestion, you need to add two firewall policies.
You may also add security profiles (IPS, AV and so) to the first policy.
Doing that way should be quite secure.
Hello @k1rusty ,
Thank you for contacting the Fortinet Forum portal.
As explained by my colleague Eric and AEK can consider those processes please refer below article for procedure reference
1. create a custom port on the firewall
2. Add service by creating an external public ip VIP virtual IP for Natting to a private address.
-Additionally to protect the server from unwanted traffic on public IP as well, add deny policy other than specified services to that VIP and make sure to enable match-vip on firewall policy from CLI
Best regards,
Manasa.
If you feel the above steps helped to resolve the issue mark the reply as solved so that other customers can get it easily while searching on similar scenarios.
Another option you can consider is using SSL VPN or IP Sec VPN. That would provide secure connection to the fortigate and not expose anything directly to internet.
The option for whitelisting is also a good option, whichever is better suited for your environment.
Regards,
Varun
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.