Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
papapuff
New Contributor II

Restricted certain IP on the same interface

hi there,

I want to make certain host (based on IP) can't accessible from some IPs.

the purpose is, DHCP user can't access certain hosts on the same interface. the user only can use/connect public hosts (such as network printer).

already try to make :

- policy interface_1 to interface_1, from dhcp IP to IP public hosts.

- policy interface_1 to interface_1, from dhcp IP to certain IP, blocked.

- policy route, from dhcp IP to certain IP, blocked.

alll policy use subnet mask 255.255.255.0

 

those policies not work.

 

any advice would be grateful. thank you.

1 Solution
dmcquade
New Contributor III

Typically hosts on the same subnet can communicate freely with each other because the traffic does not need to be routed, hence they will not traverse the firewall. Probably best to segment the traffic by either using different interfaces or configuring the firewall interface as a trunk on the switch and add VLAN interfaces to it. You could also create a zone for both VLANs effectively giving all devices on both VLANs the same policy and block intra zone traffic in the zone config.

 

hth

d

View solution in original post

2 REPLIES 2
dmcquade
New Contributor III

Typically hosts on the same subnet can communicate freely with each other because the traffic does not need to be routed, hence they will not traverse the firewall. Probably best to segment the traffic by either using different interfaces or configuring the firewall interface as a trunk on the switch and add VLAN interfaces to it. You could also create a zone for both VLANs effectively giving all devices on both VLANs the same policy and block intra zone traffic in the zone config.

 

hth

d

papapuff
New Contributor II

Hi,

thanks for reply.

currently vlan and use different interface not an option for us. anyway thanks for sharing.

 

thank you

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors