Description | This article describes how to block traffic from a specific region in a country which is not listed, using Crimea as an example. |
Scope | FortiGate. |
Solution |
The Geo location feature applies to countries only. Crimea does not appear in the country list as it is a region. IP addresses coming from this region are likely to be categorized as coming from 2 countries.
To block connections from the Crimea region, either block individual IPs directly (this is not realistically feasible as the IP list could be very large), or block the IP range belonging to the countries.
The list of IPs can be obtained with the following command:
If the IP falls under the required subnet, the country can be blocked as required.
Blocking an entire country IP range is not recommended unless necessary. The recommended solution is to use a threat feed.
The feed with a list of IPs can be obtained by selecting 'crimea_ip (FortiGuard filestore)'.
The URL obtained from the page can be used under the external resource field. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.