- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Editing the GeoIP database in FortiGate
I can create a GeoIP and select a country to distribute the rules to the region at once. But what if I want to add or exclude some addresses in this list? I have Fortigate-600D-LENC (that is, it is not connected to cloud services and auto-updates) and I have not found a way to view the database of addresses included in the GeoIP of a particular country.
With respect,
Daniil Dubosarskij
cit.rkomi.ru
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Thank you for your question. You can manually override that specific IP range will belong to different country:
Or other option is to do it with 2 firewall policies:
First firewall policy will allow traffic with specific ranges that you want to allow.
Second policy will block access based on GEO-IP addresses.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Daniil,
This article shows the commands: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Commands-to-verify-GeoIP-information-and/t...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Thank you for your question. You can manually override that specific IP range will belong to different country:
Or other option is to do it with 2 firewall policies:
First firewall policy will allow traffic with specific ranges that you want to allow.
Second policy will block access based on GEO-IP addresses.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you, I think this is the maximum I can do in this situation. Of course, I have already figured out myself that you can add addresses to the policy manually, and without the ability to automatically determine the country of the address, it seems to me that it is easier to do this than using the console to specify the country.
With respect,
Daniil Dubosarskij
cit.rkomi.ru
