Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
imran
New Contributor

Want to block ip over the local network

Hi

We are using an application over lan which isnot password protected.I want to allow several user to access this ip based web application(over Lan)and want to block to all other users on different vlans,I know we need to make a group of ip pools and add all vlans ip,but next unable to find.Currently using Fortigate 1000c firewall

 

Thanks

1 REPLY 1
Somashekara_Hanumant

Hi,

 

I you want to allow the web application for some of your user VLAN's, then first you need to make user group for those you wanted to allow.

 

Then create a firewall policy from  source interface (where the users reside) to destination interface (where the web application resides) and select the source address as allowed group and destination address as web application server address.

 

And place this policy on top of all other policies, if you don't have any other policy from this source interface to destination interface, then no need to create another policy to deny the traffic for other users, if you have other policy to allow, then create another policy below this  policy with destination address as 'web application address' and select the source address as all, with action 'Deny'

 

Now only allowed users are able to access the web application server, rest will be denied.

 

Cheers,

Somu

EMEA Technical Support
Labels
Top Kudoed Authors