Created on 12-17-2011 10:49 PM
Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Wow, seriously? So if I set an accept policy for Internal/all/http -> WAN/all/http, it also allows all http traffic inbound???First -- I hope I have understood the question here. This policy would allow all originating and RETURN traffic that originated with that firewall rule. It doesn' t open up your firewall to all incoming traffic from any source. I hope that' s clear. I' ve worked with some firewalls where it was necessary to create separate rules on both the LAN and WAN side for all traffic. Fortinet is not like that. A single rule will allow return traffic. If you want to accept traffic that originated from WAN --> LAN, you would need to explicitly create a rule for that. For example, if you had an internal web/ftp site. And this rule, conversely, would allow allow the corresponding LAN --> WAN return traffic that originated with that rule. Handshake -- hopefully the above answers your question as well.
Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.