Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Configure FortiGate 60D to Allow ALL traffic to a specific destination

Posted on 2016-08-23
6
Medium Priority
?
125 Views
Last Modified: 2016-09-05
Hi,

I have a fortinet firewall device which Ive inherited which needs a firewall added so all traffic from a specific address as full access in and out. Does anyone on EE have any experience with this firewall?

Thanks in advance
SycamoreIT
0
Comment
Question by:SycamoreIT
  • 3
  • 3
6 Comments
 
LVL 22

Accepted Solution

by:
Jakob Digranes earned 2000 total points
ID: 41767468
should be fairly easy. Log in - go to policy and object. create an address object for the IP-address. Choose interface any and subnet mask 255.255.255.255

then go to policy - choose NEW and create and from INTERFACE (which is the interface where the specific address is located, like for instance LAN) - and address object as FROM address. Then choose DESTINATION interface and address ANY. Service choose ANY and schedule - ANY
If needed, add NAT to rule. If you need traffic to go to internet or simply needs NATing
0
 

Author Comment

by:SycamoreIT
ID: 41770159
Hi Jakob,

This is what I have so far. Not sure if the Incoming interface is correct? Im setting up a rule for our IP phones which are on our local lan so will "any" do for this option? In source Address, Ive select a predefined group which covers our local lan, outgoing interface, Ive selected our Virgin Line, Destination ive inserted the IP address we want our phones to connect to and thats as far as I got.

Can you advise please?
experts.png
0
 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 41776112
You need to Enable NAT
0
New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

 

Author Comment

by:SycamoreIT
ID: 41777885
Hi Jakob,

I have implented the above, how can I test if its working?

Ta
SycamoreIT
0
 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 41777913
you could perhaps connect a computer within that address range, and do a telnet to servers you want to reach
0
 

Author Closing Comment

by:SycamoreIT
ID: 41784316
Thanks
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
Integration Management Part 2
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…
Suggested Courses

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question