FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Rajan_kohli
Staff
Staff
Article Id 268710
Description

This article shows how to block geolocations for SSL-VPN and management access with a local policy.

Scope  FortiGate v6.x.x and v7.x.x.
Solution
  1. Create a geolocation-based address object to block. Navigate to Policy & Objects -> Addresses and create a new address.

address.PNG

 

  1. Go to the CLI and configure a local policy as shown in the picture below. For srcaddr, supply the name of the address created in step 1.

local in policy.PNG

 

The name of the address created above is 'china', so the following configuration is used in this example:

 

config firewall local-in-policy

edit 1

set intf "any"

set srcaddr "china"

set dstaddr "all"

set action "deny"

set service ALL

set schedule "always"

set status "enable"

end

 

Related article:
Technical Tip: Restricting/Allowing access to the FortiGate SSL-VPN from specific countries or IP ad...