hi
I have a server configured as a vip in my fortigate to be accesses from internet. I want to block it's admin page. (my.domain.com/admin) . I tried the policy with deep packet and ssl inspection along with creating a webfilter and blocked *\admin* but still admin page reachable from internet. how can i block admin page?
Solved! Go to Solution.
Hi @rezafathi ,
Please use the "Protecting SSL Server" option and install a valid server certificate on your FGT to decrypt and inspect traffic destined to the real server.
Hi @rezafathi ,
Which one did you use, Simple, WildCard or Regex?
Anyway, why did you put a backslash in the entry?
*\admin*
hi
I tried with simple and wildcard and also removed / but still admin page is accessible from internet.
Hi @rezafathi ,
Please provide:
1) The firewall policy with VIP applied;
2) The VIP configuration;
3) The SSL Inspection profile configuration;
4) The URL Filter list configuration.
here is the screenshots you requested :
Hi @rezafathi ,
Just like what I expected, you used Certificate Inspection for the SSL Inspection profile.
In this way, FGT will detect the hostname only, not the full URL.
You must use Deep Inspection to detect the full path with the "admin" word.
i used deep packet inspection but when i want to open the page from internet it shows certificate error and also admin page still opens.
any help?
any help?
Please share your SSL/SSH Inspection profile used for this VIP traffic.
User | Count |
---|---|
2539 | |
1352 | |
795 | |
642 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.