Skip to main content
chakravarthinakka
New Member
November 30, 2022
Question

GEO blocking is not working properly

  • November 30, 2022
  • 5 replies
  • 4388 views

I have created GEO blocking policy on top of the policies , I have blocked Russia specifically. But the following ip from Russia 5.8.16.163 , As per GEO blocking policy its not blocked. I already enabled match-vip on this policy.

 

Please help why Fortinet not able to block the geo block correctly

5 replies

Toshi_Esumi
SuperUser
SuperUser
November 30, 2022

There are two separate policy sets:

- Firewall Policy (config firewall policy)

- Local-in Policy (config firewall local-in-policy)

 

Firewall Policy handles traffic coming in one interface and going out another interface. Local-in Policy handles traffic hits the FGT itself like IPsec, SSL VPNs, and other FGT initiated traffic's returns. 

 

Did you put the your GEO blocking policy in the local-in-policy? Or firewall policy?

 

Toshi 

 

chakravarthinakka
New Member
November 30, 2022

it is firewall policy , traffic coming from outside to inside 

Toshi_Esumi
SuperUser
SuperUser
November 30, 2022

So you're saying you have some VIP policies to allow outside parties to come through the FGT and forwarded to internal servers like Web server, FTP server, etc.

Then the traffic from Russia is actually hitting those internal servers, right?

 

You need to share the actual policy GUI or CLI by masking some proprietary info as well as the GEO address definition the policy is using. 

 

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!