Configuring a firewall policy to allow access to EMS
To configure a firewall policy to allow access to EMS:
FortiGate should allow access on TCP/443 for client download and TCP/8013 for telemetry.
- On the FortiGate, go to Policy & Objects > Virtual IPs.
- Click Create New.
- Input the following values:
Field
Value/configuration
Name
Telemetry-VIP
Interface
port3
Type
Static NAT
0.0.0.0
Map to IPv4 address/range
10.88.0.1
Services
HTTPS. Create a new service called Telemetry, which has its destination port set to TCP 8013.
-
Click OK.
-
Go to Policy & Objects > Firewall Policy. Click Create New.
-
Input the following values:
Field
Value/configuration
Name
WANtoEMS-Telemetry
Incoming Interface
port3
Outgoing Interface
port2
Source
All
Destination
Telemetry-VIP
Schedule
Always
Service
HTTPS, Telemetry
Action
ACCEPT
Log Allow Traffic
Enabled, All Sessions
-
Click OK to save.