Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kesha
New Contributor

Port Forwarding and Ping Disable 60B

Dear i have Fortigate 60B and i make port forwarding from static ip to private ip but i can access from internal network with stistc ip ineed to disable it from internal and i access it from external and i need to disable ping from internal can`t any one ping to any site for example google,com thanks so much and wait you reply ASP
6 REPLIES 6
Nihas
New Contributor

Regarding PING, Will it help if you place the below policy on top of all the policies? Src Int - LAN Src Add - All Dst Int - WAN Dst Add - All Service - ICMP Action - Deny Regarding the first point, Are you able to access the internal resource through the STATIC IP ( VIP)?
Nihas [\b]
Nihas [\b]
kesha
New Contributor

dear nihas thanks for you r quick response i have to ISP wan1 and wan 2 wand 1 is stitc ip wan 2 is adsl with private ip i make port forwading and working from outside without any problem but i need to not access it from internal got it bro :)
kesha
New Contributor

Dear Nihas Any update Bro :)
Nihas
New Contributor

Hello, I guess you are using a single STATIC IP for both NATing ( From internal machines to access internet) and as a VIP with portforwarding ( To access the internal machine from outside) if that is true, you may have to place a policy to block the connections from your source IP. Soruce int - any source add - your static IP address (If you are using any other IP' s for NATing you can place that IP) Destination inter - WAN 1 Destination Address - your static IP ( VIP) Service - Any ( Can be blocked the particular service -, https, rdp etc) Action - Deny. Just try out and see.
Nihas [\b]
Nihas [\b]
kesha
New Contributor

Bro really you r amazing i did it thanks bro can i if i need thing sent to you massge :)
kesha
New Contributor

bro i have last issue please i make disable from internal for my VIP range without any porblem but i need to disable sip from internal i try to custom service but still work from internal how can to custom ports to can disable sip from internal like VIP range
Labels
Top Kudoed Authors