Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

allow connection from dynamic ip addresses to fg

Hello. I would like to know if there is a way to allow certain non fixed ip address to connect to the fortigate unit, wich has a fixed ip address. I can register those client ip addresses in a dynamic dns site, and create a firewall policy in the FG to allow connections to the FG from the dyndns registered names, but is there a way to have that information up to date? I mean that the remote ip address can change often and I may need some periodic update or something else on the fortigate side to know the last ip linked to the dyndns name. Can it be done in an easy way? How often is " refreshed" the cache from a FQDN stored in the fortigate firewall addresses? It would be great to allow vpn ssl connections without leaving open service to more than the necessary ip addresses. I' m running v4.0 mr2 patch 7 right now on a FG100A. Thanks in advance Sorry about my bad English.
2 REPLIES 2
Carl_Wallmark
Valued Contributor

Hi Rsanso, and welcome to the forums, You can use an " address" and set this to FQDN, and enter the address. Then you can configure a " cache-ttl" in the CLI: config firewall address edit <nr of your address" set cache-ttl <a number> end the cache will update itself when this ttl is reached.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Not applicable

Great! I guess that' s what I was looking for. Thanks!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors