網路攻擊很猖狂
FortiGate 設定 VPN policy 之後沒有反應
Hi, you cannot block IPSec VPN traffic destined to the Fortigate IP itself with usual Security Rules - they only manage traffic PASSING the Fortigate from one interface to another.
To achieve that you need to use Local-in policy (viewable in GUI but editable in CLI only).
So your policy would look like (this will block ALL access from Ban_IP (only) to Fortigate, IPsec VPN, SSL VPN, Admin GUi etc. If you want to block just IPsec, set service accordingly):BAN 掉一些故意來試的
config firewall local-in-policy
edit 1
set intf "wan1"
set srcaddr "Ban_IP"
set dstaddr "all"
set service "ALL"
set schedule "always"
set action deny
set status enable
next
end直接鎖定只有台灣的 IP 才可以用 VPN
錯誤嘗試鎖定機制
Last updated