Hi !
I have a Fortigate 90d model, and i have to open ports like 6080, 1433 and 1434. I wish that those ports to be open only to a single internal IP address
What should I do for make this simple task ?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Non-port forwarding VIPs and port-forwarding VIPs to the same destination address are mutually exclusive!
Think of a non-port forwarding VIP as forwarding ALL ports, including the single port you already have defined in a port-forwarding VIP. Imagine traffic arriving for that destination port - which VIP should then respond?
This is ambiguous and as such not allowed.
@George:
just define one VIP for each port you want to expose to the public interface (I'm assuming that is what you meant). To facilitate the policy, group those VIPs into a VIP group and use that as the destination address in the policy.
Pretty straight forward and easy.
Create custom services using those ports
Create a new policy Lan -> Lan
Set Source and Destination as Node A and B
Allow Services -- custom services created for those ports in the new policies
Just to confirm, are you looking at these ports to be open for inbound traffic (ie internet hits those ports and it gets routed to single internal IP address) or outbound traffic (only single internal IP address is able to reach the internet on those ports)?
For inbound traffic you will need to create a VIP, custom services and link them both in a policy (http://video.fortinet.com/video/116/port-forwarding-5-2)
For outbound traffic follow nn's steps (policy needs to be LAN > WAN, Node A > Any)
I'm trying to do the same thing for a FortiGate 30b. Every time I try to create a VIP, I get a "A duplicate entry already exists" error, but the only entry in the VIP list has no port forwarding.
Any ideas?
Non-port forwarding VIPs and port-forwarding VIPs to the same destination address are mutually exclusive!
Think of a non-port forwarding VIP as forwarding ALL ports, including the single port you already have defined in a port-forwarding VIP. Imagine traffic arriving for that destination port - which VIP should then respond?
This is ambiguous and as such not allowed.
@George:
just define one VIP for each port you want to expose to the public interface (I'm assuming that is what you meant). To facilitate the policy, group those VIPs into a VIP group and use that as the destination address in the policy.
Pretty straight forward and easy.
I think he is looking for internal to internal from the post. He will also need to create address objects, and a deny I think.
Under Object use Virtual IPs
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.