- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate allow internet destination traficc only from http to any port.
Somebody knows the way to allow internet destination traffic in fortigate only from the HTTP type to any port. Regrats.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Mod.Smilzo wrote:Somebody knows the way to allow internet destination traffic in fortigate only from the HTTP type to any port. Regrats.
Hi there,
So, your question is how to filter HTTP1.x or HTTP2 traffic on the Fortigate? I'm not so sure about if I understand your question.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No what i want to do is allow all the outbound trafic only by http protocol . I mean if someone wants to use FTP protocol , should use over http no over FTP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So in this case, I think you should better list all unwanted services and create one blocking policy, and put this policy in the top of other allow policies.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Mod.Smilzo wrote:No what i want to do is allow all the outbound trafic only by http protocol . I mean if someone wants to use FTP protocol , should use over http no over FTP.
So in this case, I think you should better list all unwanted services and create one blocking policy, and put this policy on the top of other allow policies.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think he only wants to allow HTTP traffic, no matter what port is used, like NGFW mode.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It appears that he wishes to filter outbound traffic.
Create a policy that allows only the HTTP protocol to destination 'all' and apply the NAT checkbox. The source interface will be where your PCs/servers reside (internal
That is the simple answer if I understood your question.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@ericli_FTNT if i did that , is somebody wants to use the FTP protocolo over 21 port its not allowed , because it has to be FTP over HTTP thats what im loocking for. I NEED ALL THE SERVICES , BUT NEED ALL OVER HTTP.
Regrats
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@rwpatterson , yes dude thats exactly what im looking for , filter outbound traffic but by service or protocol.
So its like if someone wants to use FTP protocolo , should use over HTTP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@OHIGL dude i miss underestand , thats exactly what i want to do , HTTP OUTBOUND TRAFIC to anyport , i miss underestood my boos whit the protocols ... !! Only need , allow http trafic to anyport , becouse when im on a streaming with someone , they use over http a few ports random and i have problems , becouse a have to allow manualy etc. So if i have allowed all the ports over http i will not have that problem anymore.
