Hello,
we have Fortigate v7.2.4 and Forti EMS v7.0.7
In Forti EMS I have created a zero trust tagging rule. To test, simply whether the file c:\temp\test.txt exists.
I can use this rule in a policy on the Fortigate (IP/MAC Based Access Control).
We use this for SSL VPN dial-ins.
For example, a VPN-Client should only be able to ping an internal server if the file c:\temp\test.txt exists on the VPN-Client. This also works perfectly.
But we're going in the other direction. A VPN -Client should only be able to be pinged from an internal server if the file c:\temp\test.txt exists on the VPN-Client.
That does not work. Is that even possible?
Thank you
Martin
Hi,
So basically, a device would be tag-ed if that file exists.
You could try and use that tag as destination in the rule, just a thought.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.