Created on 04-12-2023 01:46 AM Edited on 04-12-2023 10:07 PM By Anthony_E
Description | This article describes how to allow traffic from certain clients in the blocked country list to access VIP servers. |
Scope | FortiGate. |
Solution |
In this scenario, a VIP configuration for internal servers is used. A policy (test1) with source as specific countries and destination as VIPs configured to block traffic from specific countries to the server for which VIP is configured.
Now all traffic coming from a blocked country will hit the VIP policy first and get blocked. If creating a policy (test2) for a specific source and destination is the IP address of the server, the traffic will still hit the VIP policy and will get blocked.
If there is a requirement to allow traffic from a client in the blocked county list to access the VIP servers, a policy (test3) has to be created with the source as the required IP, and the destination as the VIP server IP. It should be placed above the block policy.
Related articles: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.