Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kesha
New Contributor

disable ports from internal to external

Dear i make before post to i need to disable i can access my server`s from internal with VIP Ip i need to access from internal by internal ip and from external with external ip and MR Nihas Help me now i have ppx and i have soft phone i my soft phone i can access it my EX by VIP from Internal inned to deny this i make policy and i disable port 5060 but still i can my soft phone can register by real ip from internal can you help me my forti gate 60B
13 REPLIES 13
SecurityPlus
Contributor II

Very sorry but I can not completely understand the question. Can you restate the question please?
kesha
New Contributor

Dear i have ppx and i have soft phone in my laptop i need to disable sip port to i dodn t need this soft phone connected from internal but note i make policy and i disable port 5060 but still i can register from internal
Nihas
New Contributor

Can you please answer the below queries.? Q. Where is the PBX located? Is it located outside or internal? Q. Do you want to block the SIP for all machines or only for you. Q. Have you placed the policy under both WAN links. Q. Are you sure ,you placed the policy above the normal internet traffic? Q. Did you include both TCP & UDP for SIP port? And please do not mention any one' s name in irrelevant or different threads.. :) Thanks
Nihas [\b]
Nihas [\b]
kesha
New Contributor

Can you please answer the below queries.? Q. Where is the PBX located? Is it located outside or internal? Q. Do you want to block the SIP for all machines or only for you. Q. Have you placed the policy under both WAN links. Q. Are you sure ,you placed the policy above the normal internet traffic? Q. Did you include both TCP & UDP for SIP port? And please do not mention any one' s name in irrelevant or different threads.. :)
1Q.located inside my comapny 2Q.i bloack sip tcp and Udp 3Q.you can see my screen shoot
kesha
New Contributor

any one here :)
netmin
Contributor II

You can try a feature recently mentioned in another post:
 config firewall policy
  edit 6
   set match-vip enable
  next
 end
 
kesha
New Contributor

i don' t understand can you more explane please
netmin
Contributor II

It appears that you attempt in policy #6 to block traffic to your external address (" real" ). However, the policy may not match the VIP(s) defined on this address, this is when the option ' match-vip' is used. As the option is not available on the GUI, you need to connect to the CLI and configure the option in policy #6 as shown.
kesha
New Contributor

but everything is work like i can`t access this real ip from internal https and http everything work but sip not work how :(
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors