Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ITLER
New Contributor

Firewall between 192.168.1.50 and 192.168.1.60 in Fortigate 60F

I want to let traffic flow between the two PCs 192.168.1.50 and 192.168.1.60 only over certain ports, e.g. 45000.  For this purpose, Fortigate 60F is to be interposed

But I can't do it. 

 

The two PCs are currently directly connected to each other with a cable on the second network card.

 

 

What should I do?

can someone help me plz.?  best step by step

 

2 REPLIES 2
edomi
Staff
Staff

You can create a custom service with a specific range of ports and apply that to the policy allowing traffic.

config firewall service custom
edit <name>
set protocol TCP/UDP
set tcp-portrange <destination port range>
set udp-portrange <destination port range>
next
end

 

Find below KB describing the steps:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-create-custom-service-port-in-Forti...

AEK
SuperUser
SuperUser

Filtering intra-VLAN traffic is not so obvious because they are on the same L2 segment. The simple way is to put the hosts in different VLANs. If you can't do so then you can filter the traffic at some conditions:

  • If you have a FortiSwitch connected to your FortiGate
  • Or use your host's OS firewall

I'll not mention the third option which is to configure your FG (or VDOM) in transparent mode.

AEK
AEK
Labels
Top Kudoed Authors