Skip to main content
Hemant6737
New Member
August 4, 2024
Question

Fortigate Any to wan vs Lan to wan

  • August 4, 2024
  • 1 reply
  • 1077 views

Dear Community,

 

I am facing issue that when I create a policy from LAN to WAN and my all traffic is passing without issue, but when I want to block certain countries and IP from all the port like DMZ, LAN (inside to WAN) it's not blocking at all in the Any to WAN policy, I am confused about any to wan and Lan to wan that which policy gets  priority. FortiGate #policy #600e

1 reply

mpeddalla
Staff
Staff
August 4, 2024

Hello  @Hemant6737 ,

 

Thank you for contacting the Fortinet Forum portal.

-In general, FortiGate would check or policy from top to down in order to block traffic from any country or IP please refer article below steps and verify if you have any Virtual IP then enable match-vip as well on firewall policy from cli.

article:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-by-country-or-geolocation/ta-p/196741

 

-You can consider creating local in policy as well as below:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Blocking-Inbound-Access-from-Specific-Country-IP/ta-p/264818

 

 

 

 

 

Best regards,

Manasa.

 

If you feel the above steps helped resolve the issue, mark the reply as solved so that other customers can get it easily while searching for similar scenarios.

nradia_FTNT
Staff
Staff
August 4, 2024

Additional information on why to avoid ANY in the interface for the firewall policy:

https://community.fortinet.com/t5/Support-Forum/how-to-use-quot-any-quot-as-outgoing-interface-in-firewall/m-p/57393

 

It is always better to mention well defined addresses (e.g. 192.168.0.x, 172.16.1.x etc) rather than using "any" to mitigate security related issues that can happen when using "any" in the interface section of the firewall policy