Created on
09-20-2006
12:00 AM
Edited on
11-10-2025
07:08 AM
By
Stephen_G
| Description | This article describes how to block an IP address. |
| Scope |
FortiGate. |
| Solution |
To block an IP address, create an address entry and create a firewall policy to block the address.
Create an Address Object.
Note that if blocking an internal IP address, set the netmask to 255.255.255.255, or /32. Otherwise, it could block the entire subnet.
CLI commands:
set subnet 172.16.1.30 255.255.255.255 next
Create a Firewall Policy.
Creating policy from CLI commands:
config firewall policy set action deny <----- Action to deny logs. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.