FortiADC
FortiADC enhances the scalability, performance, and security of your applications whether they are hosted on premises or in the cloud.
Khidzir_MN
Staff
Staff
Article Id 416669
Description This article describes how to allow or block IP addresses for a specific country.
Scope FortiADC and FortiADC-VM.
Solution

Allow IP for a specific country.

 

Example:

Allow IP from Malaysia and deny IP from other countries.

 

Step 1: Configure the Geo IP Protection at Network Security -> Geo IP Protection

 

allow_from_malaysia.png

 

Step 2: Select the configured Geo IP Protection in Step 1 at the respective Application Profile for the respective Virtual Server under Server Load Balance -> Application Resources -> Application Profile.

 

application_profile.png

 

Step 3: Verify from the GEO Security Log:

 

sample_log_allow.png


Block IP from a specific country.

 

Example:

Block IP from Malaysia and allow IP from other countries.

 

Step 1: Configure the Geo IP Protection under Network Security -> Geo IP Protection.

 

deny_from_malaysia.png

 

Step 2: Select the configured Geo IP Protection in Step 1 at the respective Application Profile for the respective Virtual Server under Server Load Balance -> Application Resources -> Application Profile.

 

application_profile.png

 

Step 3: Verify from the GEO Security Log:

 

sample_log_deny.png


Related document:
Using the Geo IP block list - FortiADC 8.0.0 administration guide

Geo IP Allow List - FortiADC handbook