NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
I was hoping adding a policy to deny all international source addresses before our allow policy would do the trick - is that not doable?You may want to rethink this strategy, considering the number of IP address checks you would be placing on the fgt each time a packet comes into the fgt (could be in the 10s of thousands. edit: ok may be not that many :-). If this fgt was acting mainly as a " firewall shield" for your internal web server I may consider it. But if the fgt is functioning as a general firewall/UTM appliance for your company you will want to minimize the IP checks, say create a fw object group of allowed countries then craft a fw policy that only allows those country IPs to that internal web server -- create another fw policy blocking everything else directed to that address. But personally, I would rather see if the web server software already has that country block capability and do the blocking/allowing that way.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
@Dave You can' t be serious! A server is a general purpose machine, not built to discard more than a few connection attempts. All in contrast to a firewall. I' ve seen many servers which failed after 10 hostile login attempts because their OS simply wasn' t engineered to handle thousands.My seriousness is pretty much limited to knowing there are web server software supposedly designed to handle thousands of IP connections and that there direct/in-direct solutions to blocking IP addresses based on country origin from ever getting/connecting to your web server. But given a choice, hands down I would go with a dedicated hardware/firewall/security appliance solution for protecting a web server. The way I was looking at Scott' s problem is his company has tasked him to use their fgt to protect their internal web server -- if the fgt is not powerful enough for the task he may consider an alternate route to the solution, even if it is not idea solution or best practice......at least until he company buys better hardware. :)
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.