Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MVIOX
New Contributor

FortiWifi 60D Administration denial

Yeah I know the title is a bit misleading, but it is accurate. Trying to lock down the device (killing administration protocols) from any physical port basically kills internet access to that port. ie. under interfaces, unselecting all administrative protocols kills internet access to network. Why? I' m trying to make sure that only administrative actions can be preformed from LAN side.
8 REPLIES 8
ede_pfau
SuperUser
SuperUser

I doubt that. You can have no admin options set on the WAN port and still have outgoing traffic. Let us know a bit more about the setup: which FortiOS, which port for WAN, which method on WAN port (PPPoE, DHCP, static?), how did you test, how does the Routing Table look like. Then we' ll see.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Bromont_FTNT
Staff
Staff

Michael, Doesn' t really make sense.... Do you lose connectivity after unchecking PING?
MVIOX
New Contributor

Sorry about the confusion, maybe this will further clarify. Anytime I get a new device, I go through and tap on each and every button to see what it does and if it breaks something. Then I go through and research each item. Kinda backwards learning but it works for me... I was actually misleading with my first post, it is not Administrative access, rather administrative status. 2 options - Up or Down. I didn' t realise I hit the down button before. I originally killed all Administrative Access' s protocols then hit the down button on the administrative status. This kills everything including the link. The key here is administrative Status. I can leave everything else alone and just hit the down on Administrative status and it breaks. Full path is System>Network>Interfaces>WAN1 Running FWF60D 5.0.7
netmin
Contributor II

' administrative down' stops the interface so that it does not accept or send packets - this is a feature to achieve exactly what you found it does.
Bromont_FTNT
Staff
Staff

Ok makes sense now.... If you bring the interface down then I would expect no traffic at all on the interface.
MVIOX
New Contributor

I would expect the same from a label that would call for interface status or interface (up - down), but labeled " Administrative Status" ? To me this would call for, well what I explained earlier, denied " Administrative Access" . Either way, thank you for the learning experience.
netmin
Contributor II

You' re welcome. This is a common term in enterprise network environments that you can find also here and here.
MVIOX
New Contributor

Cool! I try to learn something new everyday! I guess it means very little what I want to call something LOL. Thanks again!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors