Somebody knows the way to allow internet destination traffic in fortigate only from the HTTP type to any port. Regrats.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Mod.Smilzo wrote:Somebody knows the way to allow internet destination traffic in fortigate only from the HTTP type to any port. Regrats.
Hi there,
So, your question is how to filter HTTP1.x or HTTP2 traffic on the Fortigate? I'm not so sure about if I understand your question.
No what i want to do is allow all the outbound trafic only by http protocol . I mean if someone wants to use FTP protocol , should use over http no over FTP.
So in this case, I think you should better list all unwanted services and create one blocking policy, and put this policy in the top of other allow policies.
Mod.Smilzo wrote:No what i want to do is allow all the outbound trafic only by http protocol . I mean if someone wants to use FTP protocol , should use over http no over FTP.
So in this case, I think you should better list all unwanted services and create one blocking policy, and put this policy on the top of other allow policies.
I think he only wants to allow HTTP traffic, no matter what port is used, like NGFW mode.
It appears that he wishes to filter outbound traffic.
Create a policy that allows only the HTTP protocol to destination 'all' and apply the NAT checkbox. The source interface will be where your PCs/servers reside (internal
That is the simple answer if I understood your question.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
@ericli_FTNT if i did that , is somebody wants to use the FTP protocolo over 21 port its not allowed , because it has to be FTP over HTTP thats what im loocking for. I NEED ALL THE SERVICES , BUT NEED ALL OVER HTTP.
Regrats
@rwpatterson , yes dude thats exactly what im looking for , filter outbound traffic but by service or protocol.
So its like if someone wants to use FTP protocolo , should use over HTTP.
@OHIGL dude i miss underestand , thats exactly what i want to do , HTTP OUTBOUND TRAFIC to anyport , i miss underestood my boos whit the protocols ... !! Only need , allow http trafic to anyport , becouse when im on a streaming with someone , they use over http a few ports random and i have problems , becouse a have to allow manualy etc. So if i have allowed all the ports over http i will not have that problem anymore.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.