Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kesha
New Contributor

Port Forwarding and Ping Disable 60B

Dear i have Fortigate 60B and i make port forwarding from static ip to private ip but i can access from internal network with stistc ip ineed to disable it from internal and i access it from external and i need to disable ping from internal can`t any one ping to any site for example google,com thanks so much and wait you reply ASP
6 REPLIES 6
Nihas
New Contributor

Regarding PING, Will it help if you place the below policy on top of all the policies? Src Int - LAN Src Add - All Dst Int - WAN Dst Add - All Service - ICMP Action - Deny Regarding the first point, Are you able to access the internal resource through the STATIC IP ( VIP)?
Nihas [\b]
Nihas [\b]
kesha
New Contributor

dear nihas thanks for you r quick response i have to ISP wan1 and wan 2 wand 1 is stitc ip wan 2 is adsl with private ip i make port forwading and working from outside without any problem but i need to not access it from internal got it bro :)
kesha
New Contributor

Dear Nihas Any update Bro :)
Nihas
New Contributor

Hello, I guess you are using a single STATIC IP for both NATing ( From internal machines to access internet) and as a VIP with portforwarding ( To access the internal machine from outside) if that is true, you may have to place a policy to block the connections from your source IP. Soruce int - any source add - your static IP address (If you are using any other IP' s for NATing you can place that IP) Destination inter - WAN 1 Destination Address - your static IP ( VIP) Service - Any ( Can be blocked the particular service -, https, rdp etc) Action - Deny. Just try out and see.
Nihas [\b]
Nihas [\b]
kesha
New Contributor

Bro really you r amazing i did it thanks bro can i if i need thing sent to you massge :)
kesha
New Contributor

bro i have last issue please i make disable from internal for my VIP range without any porblem but i need to disable sip from internal i try to custom service but still work from internal how can to custom ports to can disable sip from internal like VIP range
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors