FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
guptas
Staff
Staff
Article Id 291538
Description This article describes how to allow specific IPs/subnets to access URLs and Block IPs which are not in the allow list.
Scope FortiWeb.
Solution

It is possible to configure a URL Access Rule as well as a Policy to allow URL access to specific IPs/Subnets.

The following example demonstrates how to allow a local IP address range to access a URL. It is possible to configure Public IPs to block public IP addresses and allow only a few public IPs. 

 

Note:

If there are IP address ranges, it will be necessary to create a URL Access Rule for each subnet.

 

Step 1: Configure a URL access Rule to allow access for IPs/Subnets.

 

Navigate to Web Protection -> Access -> URL Access -> URL Access Rule.

 

URL access allow rule-kb.png

 

Step 2: Configure a URL access Rule to block access not in the allow list.

 

URL access block rule-kb.png

 

Step 3: Configure a URL Access Policy and add an allow URL access rule on top of the block URL access rule.

 

URL access Policy-kb.png