Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
polerese
New Contributor

Fotigate - Global Deny rules

Hi Everyone,

 

I'm actually thinking about the best way to achieve something with my fortigates..

Need :

I want to have a deny rule (or several) that allow me to block some IPs from everywhere to everywhere (so from/to all my zones). We are on Interface-per-view (and we want to keep it that way)

So if i want to achieve it i have to create for each zone : x rules depending on the number of destination (and it's a lot !).

I was wondering if we can take another way to achieve this with less rules without losing the Interface-per-view.. Maybe with some header policy which i don't quite understand.

 

Thank you.

10 REPLIES 10
polerese

Hi,

 

Yes i think so. I tried on a LAB firewall to and in version 7.4.2 it seems that we don't loose the interface-per-view appearence.

I don't know when the 7.4 will be mature.. Hope it is not in too long..

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors