I can create a GeoIP and select a country to distribute the rules to the region at once. But what if I want to add or exclude some addresses in this list? I have Fortigate-600D-LENC (that is, it is not connected to cloud services and auto-updates) and I have not found a way to view the database of addresses included in the GeoIP of a particular country.
With respect,
Daniil Dubosarskij
cit.rkomi.ru
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Thank you for your question. You can manually override that specific IP range will belong to different country:
Or other option is to do it with 2 firewall policies:
First firewall policy will allow traffic with specific ranges that you want to allow.
Second policy will block access based on GEO-IP addresses.
Hi Daniil,
This article shows the commands: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Commands-to-verify-GeoIP-information-and/t...
Hello,
Thank you for your question. You can manually override that specific IP range will belong to different country:
Or other option is to do it with 2 firewall policies:
First firewall policy will allow traffic with specific ranges that you want to allow.
Second policy will block access based on GEO-IP addresses.
Thank you, I think this is the maximum I can do in this situation. Of course, I have already figured out myself that you can add addresses to the policy manually, and without the ability to automatically determine the country of the address, it seems to me that it is easier to do this than using the console to specify the country.
With respect,
Daniil Dubosarskij
cit.rkomi.ru
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.