Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Danny
New Contributor

External connectors not working in FW Policies

Hello everyone

I'm facing a quite strange problem on my FG-60F wit FW v6.4.5 build1828 (GA)

Either I do not understand the sense of a firewall or I'm not experienced enough. I'm using an IP block list connected via an external connector. The connector shows 1259 valid IP addresses

I added a new deny policy on the very top of the chain to block all traffic from WAN1 to any where the source address is in the block list.

Whatever I'm trying, this policy just does not work. I added also the current IP from my smartphone provider to the list for testing.  The IP is listed in the block list, but even so I'm still able to connect to everything which shouldn't be possible at all. If I block myself via a normal static address then is works as expected.

The IP was found in the block list

I'm still able to connect even so the bad guys

 

I really wonder if someone else has the same issue and how this could be fixed. Thank you very much!

 

1 Solution
lobstercreed
Valued Contributor

You're running into an oddity of the FortiGate.  Check out this KB article and go into CLI to enable match-vip and you should have a better result.

 

https://kb.fortinet.com/k....do?externalID=FD36750

View solution in original post

1 REPLY 1
lobstercreed
Valued Contributor

You're running into an oddity of the FortiGate.  Check out this KB article and go into CLI to enable match-vip and you should have a better result.

 

https://kb.fortinet.com/k....do?externalID=FD36750

Labels
Top Kudoed Authors