Everything is works fantastic with the DMZ setup. DMZ => WAN (works) DMZ => DMZ (works) LAN => DMZ (works) DMZ ╪> LAN (DMZ can not see the internal network) I'm wondering if there is a way to disable a DMZ from pinging another DMZ device. So far, they can ping each other. I've so far disabled the administrative ping in the Fortigate.
I've created the following:
DMZ to DMZ DENY - From DMZ - To DMZ - Source all - Destination all - Service ALL - Action DENY
They can still ping each other. Any help would appreciated. Thanks
Solved! Go to Solution.
If the traffic is not flowing thru the firewall then you can't control it. Since the src and destination is within the same broadcast domain this is not handled by the layer3 device ( aka the fw )
You could enable host based firewall if the end devices support that.
Ken Felix
PCNSE
NSE
StrongSwan
If the traffic is not flowing thru the firewall then you can't control it. Since the src and destination is within the same broadcast domain this is not handled by the layer3 device ( aka the fw )
You could enable host based firewall if the end devices support that.
Ken Felix
PCNSE
NSE
StrongSwan
That make sense. Thanks for the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1748 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.