Skip to main content
mtsi
New Member
June 20, 2024
Solved

geo blocking

  • June 20, 2024
  • 1 reply
  • 1215 views

Hello,

I would like to know what is wrong with this rule, it doesn't work at all, attacks are still coming from the countries that I have added to this rule. Thank you in advance for any suggestions.

 

1.png3.png2.png

Best answer by adimailig

Hi @mtsi ,

Are you blocking traffic passing through the Fortigate? Or are you blocking traffic destined to the Fortigate IP?

If you are blocking traffic passing through the Fortigate, Firewall Policy is effective.
However, if you need to block traffic destined to Fortigate IP, you need to configure Local-in-Policy.
https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/363127/local-in-policy

Related documentation :
https://community.fortinet.com/t5/Support-Forum/Fortigate-Firewall-policy-vs-local-in-policy/td-p/317063


1 reply

adimailig
Staff & Editor
adimailigAnswer
Staff & Editor
June 20, 2024

Hi @mtsi ,

Are you blocking traffic passing through the Fortigate? Or are you blocking traffic destined to the Fortigate IP?

If you are blocking traffic passing through the Fortigate, Firewall Policy is effective.
However, if you need to block traffic destined to Fortigate IP, you need to configure Local-in-Policy.
https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/363127/local-in-policy

Related documentation :
https://community.fortinet.com/t5/Support-Forum/Fortigate-Firewall-policy-vs-local-in-policy/td-p/317063


Thought Leadership. Security Summit. Thursday, November 12th, PGA National Resort, Palm Beach Gardens, FL.
Thought Leadership. Security Summit. Thursday, October 8th. Disney's Grand Californian Hotel & SPA, Anaheim, CA.