FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pmudgal
Staff
Staff
Article Id 331556
Description

This article describes how to block anycast address in Geo-IP blocking using a deny policy.

Scope FortiGate.
Solution
  • Anycast IP is shared between multiple servers and they can be in different locations as well.
  • The objective is to block all anycast IPs irrespective of them mentioned under destination address or location.

 

Steps:

 

Make a deny policy in which we have just added the country Afghanistan as a destination, but also enabled the feature geoip-anycast.

 

pmudgal_0-1723124494155.png

 

  • geoip-anycast enabled in policy means that if the IP is an anycast IP, the packet will hit the policy even if the IP is not in the countries list of GeoIP in the policy, so in that case, if pinging 1.1.1.1/8.8.8.8, will match the policy and packet is blocked.

 

To check the geo-location of the anycast IP:

 

pmudgal_1-1723124494156.png

 

Logs:

 

pmudgal_2-1723124494159.png