Dear All,
I would like to ask what is the relationship between the local-in-policy and the dedicated management interface? For example if my mgmt interface has allowaccess ssh, https for a trusted host, is a "deny src_ip=all dst_ip=mgmt_ip (or just dst_if=any) dst_port=ssh,https" will block also the access to the mgmt interface and lock out the trusted host from access the ssh https on that mgmt port? Or the mgmt port and its configured access in the network/interfaces is above all? Thank you
Hi, yes, the above local-in policy will block the access to FGT even from a trusted host as the local-in policy check happens first.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.