Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Fortigate Policy problem

I have a Foritgate 50A Firmware 2.50 built 251, connected to an ADSL in NAT mode. I try to add a policy to restrict an IP e.g 192.168.1.2 to access HTTP service. There is an default policy allow all, all service. However when I place the deny rules as the 1st rules, all other users/IP are also deny HTTP service. Did sent an email to fortigate, but no reply yet. Anybody please help
2 REPLIES 2
UkWizard
New Contributor

You are probably falling into the network mask trap, which is a common mistake. When you add a HOST network entry, ensure you put in a subnet of 255.255.255.255 otherwise you will still be saying the entire network (hence why everyone is getting blocked.. For example, create an address entry with the following details; 192.168.1.2/255.255.255.255 Then, only this ip will be blocked.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Thanks, manage to solve my policy issues. Appreciate your help and I found information I needed in you website too.
Labels
Top Kudoed Authors