Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sadil5102
New Contributor

Public Ip Firewall Access Blocked but Internally Allow

I have disabled my Fortinet Firewall's public IP to be accessed from outside the network. I want to allow the public firewall IP to be accessed from the internal network.

2 REPLIES 2
pminarik
Staff
Staff

For administrative access (admin GUI, SSH, etc.):

1, Enable the protocol on the WAN interface

2, Block the access via WAN with a local-in policy (use WAN as the ingress interface)

3, Configure a LAN->WAN policy (required for local-in that "goes across interfaces")

 

For VIP/etc. (=forwarded traffic): Simply enable the firewall policy with the VIP/IP pool, ensuring that only the relevant source-interfaces (LAN) are allowed.

[ corrections always welcome ]
AEK
SuperUser
SuperUser

Do you mean you want to manage your FortiGate from its WAN IP, while only accessible from inside?

If so then you can do it with local-in policy (config firewall local-in-policy), by allowing private IP addresses in the first rule and denying all the rest in the second policy.

https://docs.fortinet.com/document/fortigate/7.2.10/administration-guide/363127

 

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors