- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Prevent web application access using real IP address FortiWeb
Hello everyone,
hoping all is well with you , I am using FortiWeb to protect about 10 web servers on my network , I am using subdomain from my domain from Godaddy like ( abc.xyz.com ) and assign NATed real IP to the subdomain so users can use this subdomain to access the web applications that protected by FortiWeb, but if a user use the real IP the web application works fine but I need to prevent using Real IP I need block this , I need users to use only my subdomains , because there are many Bot scanners try to attack my web applications and using Real IP at the column ( HTTP Host )
Network Security Engineer
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi,
Could you mention the mode of deployment? Is it not reverse proxy?
Best regards,
Jin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Reverse Proxy Mode
Network Security Engineer
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So by default, traffic cannot go through directly to a real server via FortiWeb but through a VIP. Did you change any other settings?
best regards,
Jin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Or are you trying to prevent access by users using the vip/virtual server IP address? But instead access should only occur by means of a FQDN/hostname?
Best regards,
Jin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
exactly access should only occur by means of a FQDN/hostname
Network Security Engineer
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ok, this can be easily setup using protected hostname definitions where only FQDNs are to be defined, please see https://help.fortinet.com/fweb/571/Content/FortiWeb/fortiweb-admin/define_protected_host.htm
Best regards,
Jin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unfortunatly this is not working
Network Security Engineer
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It means configuration for protected hostnames is not blocking the access with IP address as hostname. Hope fqdn hostnames were added with action allow. I guess we should also define the hostname IP address and add it to the list but with action deny. Afterwards apply the same through server policy.
best regards,
Jin
