Hi there,
I have blocked one IP from outside to LAN, there is no hit also showing at policy but malicious IPs being drop under Intrusion prevention system.
The question is why ??
Before entering malicious IPs from wan to LAN, IP must be blocked If I have created policy for blocked.
thank you for early response in advanced.
Can you share the event log for the same?
You can use the 'Policy Lookup' tool under 'Firewall Policy' as well. It will tell you what policy your traffic is matching.
If you're using a VIP to allow out to in, you need to set "set match-vip enable" on the deny policy.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Firewall-does-not-block-incoming-WAN-to-LA...
Toshi
Hi @Umesh,
Agreed with Toshi. Alternatively, you need to create local-in-policy to block traffic from WAN to LAN. Please refer to https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/363127/local-in-policy
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.