Configure FortiGate 60D to Allow ALL traffic to a specific destination

Hi,

I have a fortinet firewall device which Ive inherited which needs a firewall added so all traffic from a specific address as full access in and out. Does anyone on EE have any experience with this firewall?

Thanks in advance
SycamoreIT
SycamoreITAsked:
Who is Participating?
 
Jakob DigranesConnect With a Mentor Senior ConsultantCommented:
should be fairly easy. Log in - go to policy and object. create an address object for the IP-address. Choose interface any and subnet mask 255.255.255.255

then go to policy - choose NEW and create and from INTERFACE (which is the interface where the specific address is located, like for instance LAN) - and address object as FROM address. Then choose DESTINATION interface and address ANY. Service choose ANY and schedule - ANY
If needed, add NAT to rule. If you need traffic to go to internet or simply needs NATing
0
 
SycamoreITAuthor Commented:
Hi Jakob,

This is what I have so far. Not sure if the Incoming interface is correct? Im setting up a rule for our IP phones which are on our local lan so will "any" do for this option? In source Address, Ive select a predefined group which covers our local lan, outgoing interface, Ive selected our Virgin Line, Destination ive inserted the IP address we want our phones to connect to and thats as far as I got.

Can you advise please?
experts.png
0
 
Jakob DigranesSenior ConsultantCommented:
You need to Enable NAT
0
Managing Security & Risk at the Speed of Business

Gartner Research VP, Neil McDonald & AlgoSec CTO, Prof. Avishai Wool, discuss the business-driven approach to automated security policy management, its benefits and how to align security policy management with business processes to address today's security challenges.

 
SycamoreITAuthor Commented:
Hi Jakob,

I have implented the above, how can I test if its working?

Ta
SycamoreIT
0
 
Jakob DigranesSenior ConsultantCommented:
you could perhaps connect a computer within that address range, and do a telnet to servers you want to reach
0
 
SycamoreITAuthor Commented:
Thanks
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.