Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
PawelP1
New Contributor

How to Drop known external traffic into WAN interface without logging

Hi everyone,

I`m new to forum :)

My question is:
Is there a way to drop (not block) external traffic into my WAN without logging it?
By country or by IP range or single IP?
The goal is to block certain IPs so they can't even port scan my firewall.

I can`t find too much apart from Deny ipv4 policy which still logs everything.


I have Fortigate 60F.


Thanks

1 Solution
funkylicious

Hi,

 

For traffic destined directly to a FGT interface, which logs you can see in Local traffic menu, you can go to Log Settings > Local traffic logging and disable log denied unicast traffic.

If it's for traffic destined to a VIP or some other host behind the FW, logs being visible in Forward Traffic, then you would need to disabled logs in the firewall rules for it.

---------------------------
geek
---------------------------

View solution in original post

---------------------------geek---------------------------
3 REPLIES 3
Shashwati
Staff
Staff

Hello 

Please refer to the document to block traffic using local in policy

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Use-local-in-policy-to-restrict-unauthoriz...

PawelP1
New Contributor

 

Hello,


Thank you for your response.


I set up Local in policy to block some countries, but how can I turn off logging violation traffic for local in policy?


Regards.

funkylicious

Hi,

 

For traffic destined directly to a FGT interface, which logs you can see in Local traffic menu, you can go to Log Settings > Local traffic logging and disable log denied unicast traffic.

If it's for traffic destined to a VIP or some other host behind the FW, logs being visible in Forward Traffic, then you would need to disabled logs in the firewall rules for it.

---------------------------
geek
---------------------------
---------------------------geek---------------------------
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors