Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Trbonja
New Contributor

URL in firewall rules

I'd like to create a firewall rules/policies based on URL not the IP.

Example:

- DMZ or LAN Server-one can access only abcdefg.com 

- DMZ or Server-two can access only gfedcba.com

Thank you,

T

5 REPLIES 5
Harbib
Staff
Staff

Hello Trbonja,

 

You will have to create an FQDN address and apply that address in your firewall policy.

https://docs.fortinet.com/document/fortigate/6.2.0/new-features/329154/support-for-wildcard-fqdn-add...

 

GoodLuck.

Trbonja
New Contributor

Thank you!

 

T

pavankr5
Staff
Staff

Hello @Trbonja,

 

To create firewall rules or policies based on URLs rather than IP addresses. You need to generate a  FQDN address and then incorporate it into your firewall policy.

https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/217973/using-wildcard-fqdn-a...

Thanks

Pavan

YBKruthi
Staff
Staff

Hi @Trbonja,

To allow the traffic you need to create a Firewall policy.

Within the Firewall policy you can create FQDN object with specific URL as per your requirement.

Ensure do define right source and destination  in the order of preference for the policy hits.

This should work.

 

Thanks,

Kruthi

 

mgoswami
Staff
Staff

Hi,

 

For creating policies for destination URLS, you may create FQDN and use the FQDN on the policy. You may refer to this link for the asme:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-wildcard-FQDN/ta-p/196118

BR,

Manosh

Labels
Top Kudoed Authors