Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kevin
New Contributor

Detecting a Device and Policy

Can' t seem to formulate the following policy as I get stumped by an un-editable implicit Deny. (FortiOS 5.0.9) I want a policy that does this. If you are a MAC/IPad, apply this AV/webfiltering policy. If you are anything else, continue down the policy chain. Help? K
4 REPLIES 4
TuncayBAS
Contributor II

set identify device settings in local interface. and policy type need to device identify policy
Tuncay BAS
RZK Muhendislik Turkey
FCA,FCP,FCF,FCSS
Tuncay BASRZK Muhendislik TurkeyFCA,FCP,FCF,FCSS
Kevin
New Contributor

I' ve tried that, but there is an implicit deny at the end of policy that looks to block everything that isn' t a MAC/IPad. I am unable to edit that implicit deny, not do I want to create an ALLOW ALL as it would bypass my Policy chain.
Christopher_McMullan

I' m not sure what you mean... You don' t want an implicit deny, but you don' t want an allow all action. Do you want a fall-through, so that the policy is ONLY matched if the device is an iPad or Mac? If that' s the case, upgrade to 5.2. User/device matching will be done at the same time as Layer-4 matching, meaning a match will only happen when the source/destination interfaces and ports, and schedule also align with a device type. If not, the FortiGate will continue consulting down the list.

Regards, Chris McMullan Fortinet Ottawa

TuncayBAS
Contributor II

Step :1 Step2: Step3: Step4: Step5:
Tuncay BAS
RZK Muhendislik Turkey
FCA,FCP,FCF,FCSS
Tuncay BASRZK Muhendislik TurkeyFCA,FCP,FCF,FCSS
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors