Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
OGIGuy
New Contributor

XP block

Just trying to be pro-active. Anyone have an idea how we could block access to the internet from XP boxes? Just thinking of April 10th and users or customers bringing in old machines. My switches aren' t all NAC capable. Last time I looked at a device policy, it was allow a group and block the rest. I' d like to block XP devices and then fall through to UserAuth.
9 REPLIES 9
g3rman
New Contributor

What version of FortiOS are you running?
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
OGIGuy
New Contributor

5.0.4
zlimmen
New Contributor

Any update on this one? also looking for a way to block windows xp.
OGIGuy
New Contributor

Nothing that I' ve found so far. A device rule pops you out of the rule tree.
seadave
Contributor III

This would require a lot of work depending on the number of nodes you have, but if you have the right kind of switches, you could create a VLAN and put all of the XP machines on that VLAN with a separate DHCP range and then filter outbound traffic based on that VLAN or IP if the VLAN is switch routed.
Coldfirex
New Contributor

Maybe something with Group Policy, if you have a domain, could zero out the gateway or setup a fake proxy, etc.
Dave_Hall
Honored Contributor

@Tom Fischer You may be better off just performing a wireshark or other similar packet scan to determine OS version of PCs on your network, and I think the Fortigate' s vulnerability scan (discovery assets) may produce a list of PCs (and OS version) but not sure (never used that feature). It would be interesting to know if Fortinet will be incorporating such an XP-OS detector come post-April, considering the possible security consequences. (IMHO.) If you are already using some sort of UserAuth with a web portal you may as well insert some scripting code into the portal window for detecting OS version then act accordingly based on that. Of course, this approach can be circumvented, but at least it a start (e.g. Display a warning banner about needing to upgrade).

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
OGIGuy
New Contributor

Thanks for all the input. I think I' m coming to the conclusion that we' ll have to find a solution outside the Fortinet.
Dave_Hall
Honored Contributor

I wrote...
It would be interesting to know if Fortinet will be incorporating such an XP-OS detector come post-April, considering the possible security consequences. (IMHO.)
Just noticed this article in the expanded section of the FortiGate CookBook.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Labels
Top Kudoed Authors