Skip to main content
June 22, 2026
Solved

Restrict IPSEC VPN to certain countries

  • June 22, 2026
  • 4 replies
  • 182 views

Hi all,

I read this article about restricting ipsec connections to certain countries.

https://community.fortinet.com/fortigate-3/technical-tip-restrict-ipsec-vpn-access-to-certain-countries-94688

When I attempt to implement it, I find that I cannot select any wan interfaces in an address object.

In the article example (below image) it shows External (wan1) in the interface field but when I create a new address object it doesn’t show any active physical wan interfaces in the interface field.

Would using the Zone that contains the wan interface work?

 

We are running a Fortigate 81F with 7.4.12

thanks

Best answer by sjoshi

Hi ​@jjer 

You are not able to see the wan1 interface since it is part of zone.

yes you can select the zone.

 

Also it is not necessary to select the interface under address object. You can select any while creating the address object.

But while creating local in policy you do need to select the interface

4 replies

sjoshi
Staff
sjoshiAnswer
Staff
June 22, 2026

Hi ​@jjer 

You are not able to see the wan1 interface since it is part of zone.

yes you can select the zone.

 

Also it is not necessary to select the interface under address object. You can select any while creating the address object.

But while creating local in policy you do need to select the interface

Thanks, Salon
Toshi_Esumi
SuperUser
SuperUser
June 22, 2026

Also, I would assume leaving “any” for the inerface box works for this case.

Toshi 

jjerAuthor
June 25, 2026

Thanks for the replies!

 

It seems that doing this would require disabling the detect-unknown-esp parameter.  The article below advises against this, or at least suggests this isn’t best security practice, as it would stop validation of the SPI’s for existing connections.

 

https://community.fortinet.com/fortigate-3/technical-tip-esp-packets-are-not-blocked-by-local-in-policy-95212

 

The main reason for wanting to block by country is that it’s been advised by Fortinet to move away from ssl-vpn and migrate to ipsec.  This would require setting up ipsec dial-up users for our staff (our existing ipsec site-to-site connections have static IP’s to external sites), and I wanted to put some restrictions in to deny from outside our country.

 

It is confusing though, as the first article suggests I have to disable detect-unknown-esp for local in policies to take effect, but the second article suggests that local in policies can take effect after the esp check.

 

To make it more confusing, I cannot see the detect-unknown-esp parameter in the config of our 81F running 7.4.12!

jjerAuthor
June 30, 2026

I found this article and have applied it to one of our non-critical tunnels.  Will see how it goes.

https://docs.fortinet.com/document/fortigate/7.2.0/new-features/886604/matching-ipsec-tunnel-gateway-based-on-address-parameters-7-2-8