Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor II

block vip admin page

hi

I have a server configured as a vip in my fortigate to be accesses from internet. I want to block it's admin page. (my.domain.com/admin) . I tried the policy with deep packet and ssl inspection along with creating a webfilter and blocked *\admin* but still admin page reachable from internet. how can i block admin page?

Reza F.
Reza F.
1 Solution
dingjerry_FTNT

Hi @rezafathi ,

 

Please use the "Protecting SSL Server" option and install a valid server certificate on your FGT to decrypt and inspect traffic destined to the real server. 

 

https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/55107/protecting-an-ssl-serv...

Regards,

Jerry

View solution in original post

17 REPLIES 17
rezafathi

 

Hi

screencapture-192-168-30-1-4433-utm-ssl-ssh-profile-2025-04-30-10_47_41.png

screencapture-192-168-30-1-4433-utm-ssl-ssh-profile-2025-04-30-10_47_41.png

Reza F.
Reza F.
dingjerry_FTNT

Hi @rezafathi ,

 

Please use the "Protecting SSL Server" option and install a valid server certificate on your FGT to decrypt and inspect traffic destined to the real server. 

 

https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/55107/protecting-an-ssl-serv...

Regards,

Jerry
rezafathi

hi

thanks. should i do that for all vip servers or not?

Reza F.
Reza F.
dingjerry_FTNT

I think that you can use one server certificate for multiple VIP servers.

Regards,

Jerry
rezafathi

what do you mean by server certificate? do you mean certificate for my domain?

Reza F.
Reza F.
rezafathi

thanks. will i have same security features as full ssl inspection when i use protecting ssl server?

Reza F.
Reza F.
dingjerry_FTNT

Yes, technically, it is for inbound traffic from the Internet with "protecting ssl server".  And the other option is for outbound traffic to the Internet.

 

Both have the same features.

Regards,

Jerry
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors