Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nativenoble
New Contributor II

Firewall access only accept from known hosts

Good Morning,

 

is there a way to restrict firewall access over the internet to dns hosts?

 

Regards

Klaus

1 Solution
nativenoble
New Contributor II

5 REPLIES 5
Hosemacht
Contributor II

Hey there,

 

what are you trying to archive exactly?

 

Regards

sudo apt-get-rekt

sudo apt-get-rekt
nativenoble

I have Fortigates in the network which I can only reach via a VPN tunnel. If the tunnel is disturbed, I can no longer access the box. I would now like to enable access via SSH or HTTPS, but only allow the connection of certain FQDN hosts.

Hosemacht

afik its only possible to set IP adress/ranges as trusted hosts for admin users.

But there is a 2-factor authentication for admin users too, maybe this could help you

 

Regards

sudo apt-get-rekt

sudo apt-get-rekt
SLI

Hi,

You can do it using VIP with specific port forwarding (other than 22/443), then a Firewall Policy with restricted Sources (FQDN, IP, GeoLoc, ...), but I think it's unsafe to present your firewall SSH/HTTPS admin access to Internet

 

If the VPN tunnel is disturbed, the VIP access should be too ... :) won't be a good workaround

nativenoble
New Contributor II

A redditor showed me the right way! Have tested it successfully.

 

https://community.fortinet.com/t5/FortiGate/Technical-Note-Filter-ingress-traffic-going-to-the-Forti... 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors