Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jdsauer77
New Contributor

Best way to Geo-Block / Can FNT not create a list for Fortigates?

I've been looking at how to best do geo-blocking, and my options are to set every rule I have for inbound access to only accept from specific locations, or to manually add all the ones I don't want to a rule that applies at the top of the list. With SonicWALL, WatchGuard, etc. I can select the countries I don't want and set that policy at the top, why doesn't my Fortigate have the same option?

 

As for the meat of the question, does anyone have a curated list of countries that they use and is available without a $25/month or more subscription?

1 REPLY 1
AEK
SuperUser
SuperUser

On FGT you can also select the countries you don't want and set that policy at the top.

Create new policy at the top like this:

  • Source intf: WAN
  • Dest intf: DMZ interface
  • Source: GeoIP address object (with countries you don't want)
  • Dest: DMZ subnet
  • Service: ALL
AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors