Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

FSSO group to restrict access to internet only

Hi, I have a Fortigate 80c with mr3 patch 1 running on it. I have setup FSSO agent and it has picked the groups from AD. There is a custom group called Deny Internet Access. Im not sure what steps are needed to configure this sort of access. That group wont be needing acess to internet ONLY, but would still need to be able to send/receive emails. At the moment we have an outbound and inbound policy allowing access to any server and destination as any. Please suggest. Thanks
6 REPLIES 6
Not applicable

Anyone?
abelio

Hi, I cannot see where' s the problem then; just define a group services like = dns, imap,smtp,pop3 if that are services you' re interested in and apply them to the firewall policy controlling the internet access for such group.

regards




/ Abel

regards / Abel
discoveryit
New Contributor

What we do is create a Identity Based Policy for that User Group. Then set a Web URL Filter to .* blocked. That will block all websites from the systems with those users.
FCNSP
FCNSP

So when we create an Identity based manager policy, does the policy need to be on the top of my firewall policy list? Also, should I only define that policy to restrict internet access to just outbound or inbound rule or both?
Not applicable

Hi, I cannot see where' s the problem then; just define a group services like = dns, imap,smtp,pop3 if that are services you' re interested in and apply them to the firewall policy controlling the internet access for such group.
But do we still need to turn on ID based manager policy for the above services? Also, does the rule have to be on the top of the list of the fireall policy? Thanks
rwpatterson
Valued Contributor III

Policies are read from the top down, so the first good hit gets the traffic. With identity based policies, any traffic below that shares the same source/destination pair will never get hit, so you will need to include any other groups in that policy that may need Internet access.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors