Skip to main content
larsbollas
Staff
Staff
September 23, 2024

Technical Tip: Blocking host internet access

  • September 23, 2024
  • 0 replies
  • 1768 views
Description This article describes how to block internet access for single or multiple hosts using the IPv4 deny policy.
Scope FortiGate.
Solution
  1. Go to Policy & Objects -> Addresses and select Create New Address

 

address.PNG

 

An address called '192.168.1.55/32' has been created with type subnet and IP address 192.168.1.55/32.

 

  1. Go to Policy & Objects -> Addresses, select Create new address group called Blacklisted_IPs, and add the newly created address as member:

 

addrgrp.PNG

 

  1. Go to Policy & Objects -> Firewall Policy, select Create new Ipv4 policy named No internet access, and add the Blacklisted_IPs as source address with destination address set to all addresses. Do not forget to set the action to deny.

 

Deny.PNG

 

  1. FortiGate reads the IPv4 policies from top to bottom, make sure to move the deny policy on top of the internet access policy. Drag and drop the IPv4 policies in the GUI.

 

move.PNG

 

Note:

Repeat steps 1 and 2 for additional hosts or devices. A Device MAC can also be added to the Blacklisted_IPs group:


MAC.PNG

 

newgroup.PNG

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!