Deep Dive into the FortiGate Firewall Local-In Policy: GUI vs. CLI and What You Can & Can't Do

  Рет қаралды 7,742

Travis Bonfigli

Travis Bonfigli

Күн бұрын

Пікірлер: 7
@om-ty3jf
@om-ty3jf Жыл бұрын
You are a Star, hope you make a good FortiGate series
@ghulamrasool3311
@ghulamrasool3311 2 жыл бұрын
After a very long time, another detailed and well explained video. Thank you so much sir. Always waiting for your next video.
@diptiranjansahoo5278
@diptiranjansahoo5278 Ай бұрын
Hi Sir, thanks a lot for such amazing content. Why do you stop content like this 😢 ?
@ClownzRevenge
@ClownzRevenge 2 жыл бұрын
Thanks a ton. I have been looking for a tutorial for managing local-in policies, and yours is the best I have seen so far. However, I wonder if you know this, because this has been impossible to find. That's the function of the 'set srcaddr-negate enable' function. Per my understanding, this reverses the way the local-in policy works, and by default would allow only your specified addresses. I have a few firewalls I need to put something like that in place, and I have been testing this in my lab and it appears to work how I am intending, I am just concerned with putting them on some production firewalls with as little documentation as I have been able to find. Do you have any experience with that function? Perhaps another video already? (I'm about to scroll through your videos and check) Thanks in advance.
@georgexu8196
@georgexu8196 10 ай бұрын
Thank you so much. Your video really saved me. I google but no one can explain Local-In Policy clearly.
@damiannaziomek8714
@damiannaziomek8714 8 ай бұрын
Great explanation :)
@mustdobetter6748
@mustdobetter6748 Жыл бұрын
Just to add to the topic - local-in-policy has an implicit ALLOW, so if you want to permit certain ranges to particular management service, you then have to create a "deny any" to that service, or use the negate function [carefully] as mentioned by @ClownzRevenge. Be very careful with local-in policies - do NOT do a "deny any any"!!!
Central Source NAT (SNAT) and Destination NAT (DNAT/VIP)
11:41
Fortinet Guru
Рет қаралды 29 М.
Trolling Hackers with a Honeypot and how you can too
20:08
Gnar Coding
Рет қаралды 4,1 М.
Lazy days…
00:24
Anwar Jibawi
Рет қаралды 9 МЛН
Profile Vs Policy-Based Mode
8:28
Forti Tip
Рет қаралды 10 М.
Common FortiSwitch Topologies: Ring and MCLAG
20:55
ToThePoint Fortinet
Рет қаралды 14 М.
Kerberos Authentication Explained | A deep dive
16:52
Destination Certification
Рет қаралды 360 М.
Fortinet: Troubleshoot 5 IPSec Site-to-Site VPN Scenarios - FortiGate
16:02
ToThePoint Fortinet
Рет қаралды 39 М.
FortiGate 60F HA Cluster Build
22:25
Fortinet Guru
Рет қаралды 54 М.
You want a real Name Server at home? // DNS
32:31
Christian Lempa
Рет қаралды 279 М.
GEO BLOCKING THE RIGHT WAY!!!
7:52
Forti Tip
Рет қаралды 12 М.