Hello,
we have Fortigate v7.2.4 and Forti EMS v7.0.7
In Forti EMS I have created a zero trust tagging rule. To test, simply whether the file c:\temp\test.txt exists.
I can use this rule in a policy on the Fortigate (IP/MAC Based Access Control).
We use this for SSL VPN dial-ins.
For example, a VPN-Client should only be able to ping an internal server if the file c:\temp\test.txt exists on the VPN-Client. This also works perfectly.
But we're going in the other direction. A VPN -Client should only be able to be pinged from an internal server if the file c:\temp\test.txt exists on the VPN-Client.
That does not work. Is that even possible?
Thank you
Martin
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
So basically, a device would be tag-ed if that file exists.
You could try and use that tag as destination in the rule, just a thought.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.