Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ashok_kumar
New Contributor

Reg:Unrestricted user

Hi Guyz i have doubt. One of our user wants internet unrestricted access . Am created group unrestricted also created the user on IP base. also applied policy .Still that user cant access internet.Can you help me on this.

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
16 REPLIES 16
hklb
Contributor II

Hi, You have created a dhcp reservation and create an object for this IP ? Is that correct ? (I' m not sure I understand correctly..) Are you sure of your policy order ? And remove the restriction on this rules ? The more specific rules need to be at the top.
Nihas
New Contributor

I assume that the un restricted access means to access social media ,P2P etc. If that is true. There are many ways to achieve this. The common and simply way is describing below ( Experienced users can provide more feasible option though) 1. Create a new web filtering profile with a name something like " Excluded users_WF" a. Block " Security Risk Category" 2. Create a new Application control with a name something like " Excluded users_AC" a. Create a new application sensor to block " Botnet" 3. The same way you can create security profiles with less restriction for other UTM features like DLP ,Email etc. 4. Create a the IP address of the particular machine in the address object. 5. If multiple machines you want to add you can create a group and add those IP' s into it. ( ie, Excluded user group) 6 . Create a new firewall policy on top of the current internet policy and configure as below. a. Source interface - LAN b. Source address - Excluded user group c destination int - WAN1 / WAN2 ( or virtual wan link) d- Destination address - any e- service - all f - NAT - enable. UTM - a . Antivirus - default b- web filtering - Excluded users _ WF c- application control - Excluded users_ AC d - SSL deep scan - enable ( if you don;t want to use other UTM features make it disable) 7 Try to surf from the particular machine, and see whether the user is able to access the restricted sites .
Nihas [\b]
Nihas [\b]
ashok_kumar
New Contributor

Yes one of our manager want everything.I did the work using IP base but already DHCP enabled in ourFGT.Right now am created a user group My doubt is have one Webfilter policy and Application policy..so creating another one..is no issue right?

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
hklb
Contributor II

In menu " global - config - feature" , you have a feature called " multiple security profiles" . Like this, you will able to create more that one security profile.
ashok_kumar
New Contributor

ok

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
ashok_kumar
New Contributor

Is it possible through MAC instead of IP?

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
ashok_kumar
New Contributor

PLs find screen shot

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
ashok_kumar
New Contributor

fyi

ashok kumar

Network Engineer

CCNP/MCSA

 

ashok kumar Network Engineer CCNP/MCSA
hklb
Contributor II

I think no, it' s not possible by mac address (I' m not sure) but the easier way is to create a DHCP reservation.
Labels
Top Kudoed Authors