Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tutek_OLD
New Contributor

WAN Management for specific public IP only

Hello,

I need to open for a short period of time, WAN management to my Fortigate, I know that customer connecting from specific public network subnet let say this is 64.x.x.x/24, how should I configure my Fortigate to allow management on my WAN but only with source from this public subnet?

I know that there is trusted host settings in admin setings page, but I think this is rather Firewall Policy Settings?

3 REPLIES 3
Markus
Valued Contributor

Hello,

Trusted host setting is "the easy way". If you want to block not only the login, but the gui, this is possible with local-in policies https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/363127/local-in-policies.


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
Yurisk

AS @Markus said the Trusted Hosts for System -> Admin is the way to go. 

And if you don't have substantial experience with Fortigate & CLI, I'd advise AGAINST playing with Local-in policy - you may lock yourself from management very easily, and in Fortigate there is no "undo" button :)

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
nicerobot_FTNT

Second vote for "restrict login to trusted hosts" in admin settings. LocalIn policies can only restrict srcaddr from CLI and it can get you in to trouble with a lockout. Recommended to have console access available when you start changing LocalIn. You may have to do some LocalIn restrictions during the course of an audit, but you can burn that bridge when you cross it ...

---

Opinions expressed are my own and may not represent the official opinion of my employer.

Labels
Top Kudoed Authors