Hi,
I wanted to configure selected devices to access the webapplication hosted on my public IP.
Currently my Incoming rule from WAN - LAN is Source Address - ALL Destination Address - VIP - Service - ALL
I would like to restrict the source from all to selective devices. Is is possible to create a device group and add that group to source address and the same if configured will work as such?
Obviously you're talking about device identification via registered FortiClient, is that correct?
If you will use agent-based detection sure, it will work.
If you will use agentless detection it won't because if you don't have Layer2 visibility of the devices you cannot discriminate them since you will see the MAC Address of the last Layer3 device.
No its not using forticlient. A firewall rule from WAN - LAN to use Device in the source instead of source IP.
Like Alby23 mentionned, you are able to detect devices as long as you have layer2 connectivity to them. It uses mac vendor ID to determine device type. You can't detect devices on the WAN interface, because of the routers between you and them. Your Fortigate cannot know their MAC adresses.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.