Created on 12-20-2017 01:16 AM
Hi, i have a strange behaviour in firewall rules configuration
I set the Default Action to Deny...then i tried to open only what i desire...but it does not work
The FortiADC blocks all traffic
On the other end if i set the Defualt Action to Allow and then try to block a specifi port it ignores that rule and allow all
traffic
What i'm missing?
Thanks a lot
Giovanni
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Created on 12-20-2017 02:49 AM
Hi Giovanni
My glass ball is in the repair, so you have to give me more information about your config
Do you have the rules in the right order, deny as last?
regards
Attached my configuration
Deny as default befault action...and only two permit rules for my lan (LanSupertronic) vs balanced address (ServerAT-PUB) and private address (ServerAT-VIVIANI)...because i don't know if firwall analyze traffic before balance it...
Regards
Are your virtual servers on port2? or is that a real server network?
if it is virtual servers you need to keep the egress interface empty, see from the admin guide: "Note: If you want to control VS traffic through the firewall, you MUST leave the Egress Interface as default (blank). This allows VS packets to match the firewall rule."
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.