Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JOSIAH_BOZIAH
New Contributor III

How can I bulk all the Addresses Trying to access my Remoted desktop connection.

I have Thousands of IPs trying to access my fortigate using RDP, some china, russia, usa, how can i bulk block the IPS and only allow just a few that I know to access RDP.

2 Solutions
kaman
Staff
Staff

End user will connect via RDP to an external (WAN) IP address to access the internal (LAN) host with a customized RDP port. The standard RDP port is 3389.

While configuring the RDP policy, in the Source you can add only the specific IPs which you want to allow.

Please refer to the below document:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Use-RDP-via-VIP/ta-p/210093

View solution in original post

pjawalekar
Staff
Staff

Hi Josiah,

I understood that you are facing issue as multiple IP's to access your Fortigate device using RDP and those ip's are from china, russia, usa location.

You want to allow the traffic with some specific ip's, you can do the same by allowing only the specific public ip's to be in the source of the policy.

Also you can allow/block the specific geolocation to access the RDP devices, you can refer below KB for the same. Hope it will help.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-by-country-or-geolocation/ta-...


GEO IP - Blocklisting & whitelisting countries & regions
https://docs.fortinet.com/document/fortiweb/7.2.3/administration-guide/226257/geo-ip-blocklisting-wh...

 

Regards,

Pratik

 

 

 

View solution in original post

3 REPLIES 3
kaman
Staff
Staff

End user will connect via RDP to an external (WAN) IP address to access the internal (LAN) host with a customized RDP port. The standard RDP port is 3389.

While configuring the RDP policy, in the Source you can add only the specific IPs which you want to allow.

Please refer to the below document:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Use-RDP-via-VIP/ta-p/210093

pjawalekar
Staff
Staff

Hi Josiah,

I understood that you are facing issue as multiple IP's to access your Fortigate device using RDP and those ip's are from china, russia, usa location.

You want to allow the traffic with some specific ip's, you can do the same by allowing only the specific public ip's to be in the source of the policy.

Also you can allow/block the specific geolocation to access the RDP devices, you can refer below KB for the same. Hope it will help.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-by-country-or-geolocation/ta-...


GEO IP - Blocklisting & whitelisting countries & regions
https://docs.fortinet.com/document/fortiweb/7.2.3/administration-guide/226257/geo-ip-blocklisting-wh...

 

Regards,

Pratik

 

 

 

JOSIAH_BOZIAH
New Contributor III

Thank you.

Labels
Top Kudoed Authors