Description | This article describes a scenario wherein GeoIP restriction does not work if the HTTP traffic does not match the HTTP content routing policy based on the hostname. |
Scope | FortiWeb v7.4.x. |
Solution |
In the FortiWeb configuration, there are defined content routing policies.
In the Web profile, the GeoIP list is called.
config waf geo-block-list
If there is no explicit match with the other content routing policies the default will be chosen and the web profile with the GEO IP object will deny the request of the country in case it is in the blocked list. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.