Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
thund31
New Contributor

restrict specific IP to access WAN interface+port?

hi all,

wanna ask a dumb question about limiting access from internet.

 

i have a fortigate 200D acting as edge between internet and private network.

the WAN interface on 200D got some ports open (for quick access, i know it's not safe) that maps to private network's IP and ports.

for example, ip address 100.100.100.100 is the public IP on 200D's WAN and VIP object 100.100.100.100:2345 has been opened to the internet to allow FTP access.

 

my target is to allow specific IPs from internet to access 100.100.100.100:2345 (and block the remaining).

just check the 200D admin webpage but not sure about which place is correct to set the white/black list, as shown in figure below.

 

so...I would like to know

1.which object/item/rule should I utilize on the admin webpage to achieve my need?

2. should i set the object/item/rule base on the VDOM?

can anyone provide some hints?

thanks~~!

 

b.t.w. the fw version is 5.0 on this 200D

4 REPLIES 4
lobstercreed
Valued Contributor

When you say you have ports forwarded (like 2345) for FTP access, I assume you're talking about Virtual IPs (VIPs) that you have used in a firewall policy from WAN to LAN?  If you want to limit access, you simply modify the source address in that firewall policy so that instead of "all" it is the addresses you specify.  You may need to create multiple address objects and put them in a group, but that's easy enough.

Ashik_Sheik
Contributor II

Hi,

 

You need to set up VIP under IPV4 policy and where external IP should map to real IP of FTP server with port number.Please follow below link 

 

https://kb.fortinet.com/kb/documentLink.do?externalID=10540 

 

Regards ,

Ashu 

 

Ashu
thund31
New Contributor

hey guys thanks for answering my dumb question~~!

 

frankly speaking, 

i'm talking about WAN VIP address 100.100.100.100:2345 mapping to private network FTP service 172.24.3.1:5432,

and allow specific internet IPs to access 100.100.100.100:2345 for FTP files.

that's it.

(note that the ip addresses and ports described above are just for demonstration. I would like to apply same principle to restrict access on other types of services which are mapped to virtual IP too.)

 

I'm going to try the settings that you've just provided.

thanks you so much!!

boneyard
Valued Contributor

if that was the correct answer please flag it as such

 

also version 5.0 is very old, please upgrade when you can.

Labels
Top Kudoed Authors