Hi,
I would like to implement stealth rule in FortiGate Firewall without affecting VPN, HA services and others.
I have 2 administrators that I want to allow to have ICMP, SSH and HTTPS services to Firewall and all others is denied.
How can I safely make a rule in local-in-policy without affecting other services such as VPN.
Thank you.
As you probably already know the parameters you can specify in local-in-policy are
- interface
- source address
- destination address
- service
- schedule
If the services are not unique for what those privileged users need to be able to do, you have to tweak other parameters like src/dest addresses. It's not so easy.
Instead I would recommend separating them by VPN groups and set different firewall policies. They need to logon the VPN first then they can have special privileges.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1738 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.