Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor II

block vip admin page

hi

I have a server configured as a vip in my fortigate to be accesses from internet. I want to block it's admin page. (my.domain.com/admin) . I tried the policy with deep packet and ssl inspection along with creating a webfilter and blocked *\admin* but still admin page reachable from internet. how can i block admin page?

Reza F.
Reza F.
1 Solution
dingjerry_FTNT

Hi @rezafathi ,

 

Please use the "Protecting SSL Server" option and install a valid server certificate on your FGT to decrypt and inspect traffic destined to the real server. 

 

https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/55107/protecting-an-ssl-serv...

Regards,

Jerry

View solution in original post

17 REPLIES 17
dingjerry_FTNT

Hi @rezafathi ,

 

Which one did you use, Simple, WildCard or Regex?

 

Anyway, why did you put a backslash in the entry?   

 

*\admin*

Regards,

Jerry
rezafathi

hi

I tried with simple and wildcard and also removed / but still admin page is accessible from internet.

Reza F.
Reza F.
dingjerry_FTNT

Hi @rezafathi ,

 

Please provide:

 

1) The firewall policy with VIP applied;

2) The VIP configuration;

3) The SSL Inspection profile configuration;

4) The URL Filter list configuration.

Regards,

Jerry
rezafathi

here is the screenshots you requested :

policy1.pngpolicy2.pngSSL.pngVIP1.pngwebfilter.png

Reza F.
Reza F.
dingjerry_FTNT

Hi @rezafathi ,

 

Just like what I expected, you used Certificate Inspection for the SSL Inspection profile.  

In this way, FGT will detect the hostname only, not the full URL.

 

You must use Deep Inspection to detect the full path with the "admin" word.

Regards,

Jerry
rezafathi

i used deep packet inspection but when i want to open the page from internet it shows certificate error and also admin page still opens.

Reza F.
Reza F.
rezafathi
Contributor II

any help?

Reza F.
Reza F.
rezafathi
Contributor II

any help?

Reza F.
Reza F.
dingjerry_FTNT

Please share your SSL/SSH Inspection profile used for this VIP traffic.

Regards,

Jerry
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors