Hello,
I need to open for a short period of time, WAN management to my Fortigate, I know that customer connecting from specific public network subnet let say this is 64.x.x.x/24, how should I configure my Fortigate to allow management on my WAN but only with source from this public subnet?
I know that there is trusted host settings in admin setings page, but I think this is rather Firewall Policy Settings?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Trusted host setting is "the easy way". If you want to block not only the login, but the gui, this is possible with local-in policies https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/363127/local-in-policies.
________________________________________________________
--- NSE 4 ---
________________________________________________________
AS @Markus said the Trusted Hosts for System -> Admin is the way to go.
And if you don't have substantial experience with Fortigate & CLI, I'd advise AGAINST playing with Local-in policy - you may lock yourself from management very easily, and in Fortigate there is no "undo" button :)
Second vote for "restrict login to trusted hosts" in admin settings. LocalIn policies can only restrict srcaddr from CLI and it can get you in to trouble with a lockout. Recommended to have console access available when you start changing LocalIn. You may have to do some LocalIn restrictions during the course of an audit, but you can burn that bridge when you cross it ...
---
Opinions expressed are my own and may not represent the official opinion of my employer.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.