- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why can an external device access the login page of my Fortigate?
Hello everybody, I'm working on a Fortigate 60F (v7.2.10) and I manage my Fortigate at the address:
or
https://79.x.x.x:40443 (for externals)
https://10.1.0.1:40443 (for internals)
because 79.x.x.x is the wan1 interface, I defined two local-in-policy:
login_group is an address group:
HTTPS-40443 is:
The policy n.1 works fine, if I try to access (10.1.0.1:40443 or vpn.xxx.com:40443) I correctly see the login page.
From the same network (10.1.10.0/24), another device, can't (correctly).
If I use an external device (for example my phone), connected to a different external network, it can access vpn.xxx.com:40443 and also 79.x.x.x:40443. The policy n.2 doesn't generate any log. What am I missing?
Solved! Go to Solution.
- Labels:
-
Firewall policy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I found the solution. The problem was the address 79.x.x.x. You have to include inside the policy the private address of the interface (192.168.1.4, and not the public 79.x.x.x)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I found the solution. The problem was the address 79.x.x.x. You have to include inside the policy the private address of the interface (192.168.1.4, and not the public 79.x.x.x)
