Description |
This article describes a practical approach to safeguarding the network by denying connections from IPs originating in China. |
Scope | FortiGate. |
Solution |
Navigate to 'System' and access 'Feature Visibility'. Confirm whether 'Local in Policy' is enabled.
Configure the local-in policy by setting the appropriate parameters: And in the service, it is all defined, because it is necessary to block all connections coming to the firewall in any port number.
By following these steps, it is possible to effectively block connections originating from specific country IP ranges, ensuring enhanced security for the FortiGate.
The next tip on the same topic is a bonus tip in case there is a need to allow only one country to connect to the firewall and all of the other countries to be blocked. In this example, all of the countries except China will be blocked :
The following is achieved with the use of 'set srcaddr-negate enable' which would block all of the addresses except the one configured in 'srcaddr'. One friendly reminder is that the default action in local policies is denied, therefore there is no need to configure it.
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.