Hi
We are using an application over lan which isnot password protected.I want to allow several user to access this ip based web application(over Lan)and want to block to all other users on different vlans,I know we need to make a group of ip pools and add all vlans ip,but next unable to find.Currently using Fortigate 1000c firewall
Thanks
Hi,
I you want to allow the web application for some of your user VLAN's, then first you need to make user group for those you wanted to allow.
Then create a firewall policy from source interface (where the users reside) to destination interface (where the web application resides) and select the source address as allowed group and destination address as web application server address.
And place this policy on top of all other policies, if you don't have any other policy from this source interface to destination interface, then no need to create another policy to deny the traffic for other users, if you have other policy to allow, then create another policy below this policy with destination address as 'web application address' and select the source address as all, with action 'Deny'
Now only allowed users are able to access the web application server, rest will be denied.
Cheers,
Somu
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1744 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.