Hello everyone
I'm facing a quite strange problem on my FG-60F wit FW v6.4.5 build1828 (GA)
Either I do not understand the sense of a firewall or I'm not experienced enough. I'm using an IP block list connected via an external connector. The connector shows 1259 valid IP addresses
I added a new deny policy on the very top of the chain to block all traffic from WAN1 to any where the source address is in the block list.
Whatever I'm trying, this policy just does not work. I added also the current IP from my smartphone provider to the list for testing. The IP is listed in the block list, but even so I'm still able to connect to everything which shouldn't be possible at all. If I block myself via a normal static address then is works as expected.
The IP was found in the block list
I'm still able to connect even so the bad guys
I really wonder if someone else has the same issue and how this could be fixed. Thank you very much!
Solved! Go to Solution.
You're running into an oddity of the FortiGate. Check out this KB article and go into CLI to enable match-vip and you should have a better result.
You're running into an oddity of the FortiGate. Check out this KB article and go into CLI to enable match-vip and you should have a better result.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.