Skip to main content
akamath
Staff
Staff
June 3, 2020

Technical Tip: Create ISDB objects with specific Country/Region/City

  • June 3, 2020
  • 0 replies
  • 5386 views
Description This article describes the Geographic-based Internet Service Database (ISDB) objects, which allow users to define a country, region, and city.
Scope FortiOS.
Solution

Create ISDB via Graphical User Interface (GUI).

  • Go to Policy & Objects -> Internet Service Database and select 'Create New'.
  • Under 'Type' select 'Geographic Based'.

 

new-isdb.png

 

Create ISDB via CLI:

 

config firewall internet-service-name
    edit "Test"
        set type location
        set internet-service-id 327781
        set country-id 356
        unset region-id
        unset city-id
    next
end

 

To view the entries of this location-based ISDB object, either use the following methods:

 

  1. In the table, hover over the object created, select 'View/Edit Entries'. 

 

hover.png

 

  1. Open the object, then select 'View/Edit Entries'. 

     

    test.jpg

     

     

  2. View the IP ranges in the location-based internet service from the CLI.

     


preve-kvm35 # diagnose internet-service id 327781
Internet Service: 327781(Microsoft-Skype_Teams)
Version: 00007.04412
Timestamp: 202603041214
Number of Entries: 5720
1.37.76.216-1.37.76.216 country(608) region(65535) city(65535) blocklist(0x0) reputation(5), popularity(5) domain(876) botnet(0) proto(6) port(80 443 1000-10000 16000-26000 50000-65000)

 

Note:

These objects can be used in firewall policies or local-in policies for more granular control over the location of the parent ISDB object.

Location-based customization for Internet Service FQDN is not supported.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!