Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kriu
New Contributor II

Remote connection policy for FG-60E

Please help me configure a policy for one connection. FG-60E (firmware v.7.2.10) works in transparent mode between optical modem (also in transparent mode) and main router for LAN. External IP address is on router, not on modem. When Inspection Mode works in Proxy-based (Firewall Policy), one of the devices in LAN cannot communicate with its server where it sends measurement data (blitzortung.org). Policy in Flow-base mode does not block the connection. It blocks only in Proxy-base. Is it possible to set Flow-based policy for selected remote server? Or add some exclusion in current policy? I know the addresses of servers to which data is sent.

2 Solutions
ebilcari

It should be simple from the GUI, in Firewall Policy, copy the existing policy and paste 'Above'. Set a new policy name, select the Source and create an Address for the interested device and do the same in Destination for the server. Change the inspection to 'Flow-based' and enable the policy (toggle at the bottom).

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

kriu
New Contributor II

It worked.
I created a new policy, I had to enter the server addresses only in Destination.

View solution in original post

4 REPLIES 4
ebilcari
Staff
Staff

You can create a dedicated policy specific for only this host to server traffic and position it above the existing policy.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
kriu
New Contributor II

Yes, but how to do it? - I have no experience with FG

ebilcari

It should be simple from the GUI, in Firewall Policy, copy the existing policy and paste 'Above'. Set a new policy name, select the Source and create an Address for the interested device and do the same in Destination for the server. Change the inspection to 'Flow-based' and enable the policy (toggle at the bottom).

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
kriu
New Contributor II

It worked.
I created a new policy, I had to enter the server addresses only in Destination.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors