Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
akabarasif
New Contributor III

how to create policy for LAN to LAN user ?

hi,

kindly assist me or provide a solution to restrict user to access some servers services, for example, some users use application server and some are not, so if i allow them to access and block others it will not work because below there is a policy is all to all allowed, because we have more servers for example Active directory server email server, i dont want to block some users to access some servers instead of specify policy for active directory and email server

 

2 REPLIES 2
Fullmoon
Contributor III

for me the best way to control your users services towards your servers would be migrating your server farm to different vlans or different port of fortigate.

Fortigate Newbie

Fortigate Newbie
boneyard
Valued Contributor

i dont quite get your point

 

you can't make extra rules because below those rules is a rule that allows everything

 

well if you want to achieve what you want then you need to remove that all all ALL allow rule, because that will cause this to never work

Labels
Top Kudoed Authors