Hey guys,
I have a question that I haven't been able to solve yet and I need help on how to do it.
I need the linux servers, be they debian or cent os... in fact, regardless of the system, only their proper repositories are allowed on the firewall.
For example: a debian server needs to install the NTP service and I want to release for a period only the apt-get repositories so that the analyst can run this, the rest to leave locked. Currently to perform any system update on linux or installation of new packages I need to release all targets on port 80 and 443.
Is there a way to restrict this access from linux machines on the firewall?
I tried to look for something like IP Ranges used by each distribution or a service in FortiGate's Internet Services, but I haven't found a way that suits me the way I want.
Has anyone been through this or had this need?
I don't know if that would be the best way to act either.
FortiOS is at version 6.2.7.
Thank you all.
Hello,
As far as I understand the goal is to allow traffic only towards certain linux repositories. In case I understand the scenario correctly you may consider to create firewall policy with the list of IP addresses of the servers or request new ISDB entry. Please find the form below:
https://www.fortiguard.com/faq/isdb-contact
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1748 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.