Hello guys
I am trying to config allow client in DMZ access to some specific IP address in Local Network. But I still got stuck
Do you have any advise?
Thank you very much in advance
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The policy should be as simple as:
Incoming interface: Your DMZ interface
Outgoing Interface: Your internal Interface
Source: The IP of DMZ client
Destination: IP of destination server/s in LAN
Service: whatever ports will be used
Schedule: Always
Action: Accept
NAT: Depends if you need it switch on if not leave off.
Want to add if this is one client (in the DMZ) to use /32 (e.g. 192.168.3.1/32) - you can set the service to all (any) for full access (otherwise use the dest port and set source port to 0-65535) - dest IP should be also /32 unless you really wanted access to more than one IP. Make sure to move the firewall policy up in the firewall chain, above any general access rule(s), so it is triggered. Unless you are not aware, firewall policies are processed from top-to-bottom until a matching rule is found/executed.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1561 | |
1034 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.