Skip to main content
junior
Explorer II
March 15, 2022
Question

how to block specific external IP avoiding from VPN login?

  • March 15, 2022
  • 8 replies
  • 6116 views

Hi all, as title, a stranger attempts to login our VPN from a specific external IP such as 85.56.83.8, do you know how to block it? or any other solutions?

Thanks in advance.

8 replies

Toshi_Esumi
SuperUser
SuperUser
March 15, 2022
sharmaj
Staff
Staff
March 16, 2022

Hi ,

 

If you have multiple such IPs, you can actually block them using the IP threat feed database and add that into the policy pertaining to VPN.

 

https://docs.fortinet.com/document/fortigate/6.2.0/new-features/625349/external-block-list-threat-feed-policy

ede_pfau
SuperUser
SuperUser
March 16, 2022

AFAICT, threat feed cannot be used in local-in policies.

junior
juniorAuthor
Explorer II
March 16, 2022

is there any other advice?

ede_pfau
SuperUser
SuperUser
March 16, 2022

local-in policy is the way to go. It's effective and available. What else do you need?

junior
juniorAuthor
Explorer II
March 17, 2022

Hi, it's like the commands?

config firewall local-in-policy
edit 0
set intf "WAN"
set srcaddr "81.59.52.3"
set dstaddr "all"
set service "ALL"
set schedule "always"

ede_pfau
SuperUser
SuperUser
March 17, 2022

Yup. Default action is DENY and will not show up using "show", but when you use "show full". Check to be sure.

Over time you will collect some number of 'hostile' public IPs. Put them into an address group and use the group in the local-in policy. This way, to add an address, you only have to edit the group and can leave the policy alone.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!