Solved

Configure FortiGate 60D to Allow ALL traffic to a specific destination

Posted on 2016-08-23
6
92 Views
Last Modified: 2016-09-05
Hi,

I have a fortinet firewall device which Ive inherited which needs a firewall added so all traffic from a specific address as full access in and out. Does anyone on EE have any experience with this firewall?

Thanks in advance
SycamoreIT
0
Comment
Question by:SycamoreIT
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 22

Accepted Solution

by:
Jakob Digranes earned 500 total points
ID: 41767468
should be fairly easy. Log in - go to policy and object. create an address object for the IP-address. Choose interface any and subnet mask 255.255.255.255

then go to policy - choose NEW and create and from INTERFACE (which is the interface where the specific address is located, like for instance LAN) - and address object as FROM address. Then choose DESTINATION interface and address ANY. Service choose ANY and schedule - ANY
If needed, add NAT to rule. If you need traffic to go to internet or simply needs NATing
0
 

Author Comment

by:SycamoreIT
ID: 41770159
Hi Jakob,

This is what I have so far. Not sure if the Incoming interface is correct? Im setting up a rule for our IP phones which are on our local lan so will "any" do for this option? In source Address, Ive select a predefined group which covers our local lan, outgoing interface, Ive selected our Virgin Line, Destination ive inserted the IP address we want our phones to connect to and thats as far as I got.

Can you advise please?
experts.png
0
 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 41776112
You need to Enable NAT
0
[Live Webinar] The Cloud Skills Gap

As Cloud technologies come of age, business leaders grapple with the impact it has on their team's skills and the gap associated with the use of a cloud platform.

Join experts from 451 Research and Concerto Cloud Services on July 27th where we will examine fact and fiction.

 

Author Comment

by:SycamoreIT
ID: 41777885
Hi Jakob,

I have implented the above, how can I test if its working?

Ta
SycamoreIT
0
 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 41777913
you could perhaps connect a computer within that address range, and do a telnet to servers you want to reach
0
 

Author Closing Comment

by:SycamoreIT
ID: 41784316
Thanks
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
We sought a budget ($5,000) firewall solution that would provide all the performance we needed with no single point of failure.  Hosting a SAAS web application in our datacenter, it was critical that we find a way to keep connectivity up and inbound…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
Suggested Courses

626 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question