Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Marco_Broker
New Contributor

Blocking a List of static Ip Addresses

Hi All,

            Please someone help me to block a range of Ip addresses for http and https . The ip range is 192.168.64.95 to 192.168.64.140. Am using a Fortigate 100 D

 

Can I get the steps with you to do it .

 

Thanks in advance .

 

 

 

Network Technician
Network Technician
2 REPLIES 2
ede_pfau
SuperUser
SuperUser

1- create an address object, say "bl_rng_1", as address 192.168.64.[95-140]

2- create an address group, say "blocked_nets", and add "bl_rng_1"

3- if not present, create a policy for HTTP and HTTPS only, from 'internal' to 'wan', put "blocked_nets" as destination address, select action "DENY".

 

For just one address you strictly speaking would not need an address group. But if you can block one address, there will come another tomorrow,...just create an address object and add it to the group. No fiddling with the policy in the future.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Marco_Broker

Hi Broth ,is work ,thank.Please could help for another setup .

My Boss ask me to block all website except www.mcb.mu is permitted  on ip 192.168.200/24.

I have tried  to follow the whitelist setup in the library  but unfortunately it does"t work

 

The fortigate model is a 100D

Version 5.2

 

Please help if you can thanks in advance .

 

 

Network Technician
Network Technician
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors