New FortiGate admin here. I'm looking to enable web-admin on the WAN ports, but only allow access from specific IP addresses. I've created the address objects, but am not seeing how to configure a firewall policy. There would (obviously) be no outgoing interface.
I can see a couple of suggestions coming, so to avoid those...
So, a firewall policy should be the way to go...
Any help would be appreciated!
Solved! Go to Solution.
Local policies look powerful. But, I went with something a little simpler: a Virtual IP + Firewall Policy. The virtual IP forwards the webui port through to the firewall's internal address, and the firewall policy controls who has access.
You are probably looking for local-in policy.
https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/363127/local-in-policy
Local policies look powerful. But, I went with something a little simpler: a Virtual IP + Firewall Policy. The virtual IP forwards the webui port through to the firewall's internal address, and the firewall policy controls who has access.
I didn't test it because I find it more secure to avoid publish the WebUI directly on WAN. But trough VPN is much more secure. However I find your method a good idea for hardening access to WebUI from WAN.
BTW there is another approach with loopback interface, explained by Yurisk in this article. He did it for SSL VPN but it should also work for WebUI.
User | Count |
---|---|
2609 | |
1390 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.