Got it

Can't blocking Unspecified IP addresses to login (cannot see the web admin GUI) to the firewall.

Created: Apr 20, 2019 09:10:22Latest reply: Apr 20, 2019 09:19:32 349 1 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hello everyone

I want to allow the certain IP address to login (can see the web admin GUI) to the firewall while blocking all the other IP address to login (cannot see the web admin GUI) to the firewall.

firewall policy is below:

rule name
  source-zone untrust
  destination-zone local
  source-address address-set MGMT_DEVICE
  destination-address address-set FW_MGMT
  action permit

However, the IP address that is not in "MGMT_DEVICE" can still login to the firewall

Please advise how can I block all the other IP addresses from seeing the web admin GUI?

Thank you!




Featured Answers
Popeye_Wang
Admin Created Apr 20, 2019 09:19:32

Hey!

The firewall does not support the blocking of the login page. This is because the service-manage function has a higher priority than security policies.

 Can't blocking  Unspecified IP addresses to login (cannot see the web admin GUI) to the firewall.-2918197-1

Since the service-manage function has to be enabled on the manager interface, we can't block another IP from logging in to the GUI through the firewall.
 
If you have to block it, try to configure ACL on the previous device to deny that specific IP the access firewall management IP.
View more

This article contains more resources

You need to log in to download or view. No account? Register

x
  • x
  • convention:

All Answers
Hey!

The firewall does not support the blocking of the login page. This is because the service-manage function has a higher priority than security policies.

 Can't blocking  Unspecified IP addresses to login (cannot see the web admin GUI) to the firewall.-2918197-1

Since the service-manage function has to be enabled on the manager interface, we can't block another IP from logging in to the GUI through the firewall.
 
If you have to block it, try to configure ACL on the previous device to deny that specific IP the access firewall management IP.
View more

This article contains more resources

You need to log in to download or view. No account? Register

x
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.