Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dschak
New Contributor

Whitelist Countries for VPN Access

How in the FortiGate GUI interface, can I configure white listed counties.

 

Under Policies & Objects -> Addresses I have created my allowable counties using Type = Geography and I have my 5 countries.

In the same place I have created a group called Whitelisted Counties and added the 5 countries.

 

Where do I now add this address group and what settings do I need to change to make this work?

 

Preferably through the GUI rather than the CLI.

#fortigate - firmware v6.4

Derek Schakel
Derek Schakel
6 REPLIES 6
Toshi_Esumi
SuperUser
SuperUser

dschak

Hi Toshi,

 

I did read that KB but was hoping that there would be a way of doing this via the GUI rather than the CLI.

Derek Schakel
Derek Schakel
Toshi_Esumi

I think local-in-policy config is available only via CLI. It's not so difficult.

pavankr5
Staff
Staff

Hello 
Please check this article for SSL VPN connectivity from certain countries using firewall geography addresses 
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Restricting-SSL-VPN-connectivity-from-cert...


Thanks

waqar11
New Contributor

To configure whitelisted countries in the FortiGate GUI interface, follow these steps:

  1. Log in to the FortiGate GUI.
  2. Go to "Security Profiles" and select "Geolocation."
  3. Click on "Create New" to add a new geolocation filter.
  4. Choose "Countries" and select the desired countries you want to whitelist.
  5. Save your settings, and the specified countries will be whitelisted on your FortiGate firewall.
galilio
New Contributor

Copy the rule that has the GeoIP settings. Modify the copied rule to get rid of the GeoIP settings and set the source/destination for how you want it. Then make sure it's set higher than the rule with the GeoIP active.

https://showbox.bio https://tutuapp.uno/
Labels
Top Kudoed Authors