Hello all,
I want to let subnet 10.0.0.0/8 out to the internet, however, i want to filter out 10.1.100.0/24. How do I do it in my 100F? Sorry, moved to Fortigate from a different product.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Create a deny policy for 10.1.100.0/24 then place it above a policy to allow 10.0.0.0/8.
Create a deny policy for 10.1.100.0/24 then place it above a policy to allow 10.0.0.0/8.
Thank you for the solution! In Barracuda it was all in one rule, was hoping for something like that.
If it were simply negate 10.1.100.0/24 then the rest were allowed, you could use a negate address like in the KB. But one policy doesn't seem to have a negate and normal addresses. So you still need to have two policies any way.
But even if they can co-exist in one policy, the FW would operate exactly the same way with two policies. So I don't see much benefit operation-wise. I think that's why they haven't added the feature yet. Nor strong demands.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.