Fortinet Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dubos
New Contributor III

Editing the GeoIP database in FortiGate

I can create a GeoIP and select a country to distribute the rules to the region at once. But what if I want to add or exclude some addresses in this list? I have Fortigate-600D-LENC (that is, it is not connected to cloud services and auto-updates) and I have not found a way to view the database of addresses included in the GeoIP of a particular country.

With respect,

Daniil Dubosarskij

cit.rkomi.ru

1 Solution
akristof
Staff
Staff

Hello,

 

Thank you for your question. You can manually override that specific IP range will belong to different country:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Commands-to-verify-GeoIP-information-and/t...

 

Or other option is to do it with 2 firewall policies:

First firewall policy will allow traffic with specific ranges that you want to allow.

Second policy will block access based on GEO-IP addresses.

Adrian

View solution in original post

3 REPLIES 3
amouawad
Staff
Staff
akristof
Staff
Staff

Hello,

 

Thank you for your question. You can manually override that specific IP range will belong to different country:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Commands-to-verify-GeoIP-information-and/t...

 

Or other option is to do it with 2 firewall policies:

First firewall policy will allow traffic with specific ranges that you want to allow.

Second policy will block access based on GEO-IP addresses.

Adrian
Dubos
New Contributor III

Thank you, I think this is the maximum I can do in this situation. Of course, I have already figured out myself that you can add addresses to the policy manually, and without the ability to automatically determine the country of the address, it seems to me that it is easier to do this than using the console to specify the country.

With respect,

Daniil Dubosarskij

cit.rkomi.ru