How do you properly block a specific IP or netblock?
- August 6, 2020
- 2 replies
- 22116 views
I've tried many times in the past to try and block IPs in our FortiGate 60E (firmware v5.6.3 build1547 (GA)) and I must say it's the most convoluted and confusing UI I've used to date. Which is why I'm here asking what I'm doing wrong. What I've typically done is create a new address and then set it to deny in the IPv4 Policy.
(step1.png)
Policy & Objects -> Addresses Create New -> Address Name: "45.141.84.162/32 20200805" Type: Subnet Subnet/IP Range: 45.141.84.162/32 Interface: wan1 (or all)
(step2.png) Policy & Objects -> IPv4 Policy Create New Name: "Block 45.141.84.162" Incoming Interface: wan1 Outgoing Interface: internal Source: "45.141.84.162/32 20200805" Destination: all Schedule: always Service: ALL Action: DENY Enable this policy: Checked
But i then still see traffic coming through as if it did nothing. I've also tried using IP ranges of 45.141.84.162-45.141.84.162 and that has done nothing as well. So far the only way I've seen to actually stop an IP address is to ban the IP.
FortiView -> Traffic From WAN -> Sources Filter on Source and IP Right-Click on the IP and select Ban IP I can then see the banned IP under Monitor -> Quarantine Monitor. But even then I can only ban a single IP, i can't ban a netblock. Is there a better way of going about this?
