We have someone traveling and they would like us to not block from a geo filtering standpoint in Mexico/Caribbean. I would like to give them a list of countries to pick from for us to unblock. Is there a way to export this list? Via CLI would be OK too.
Hello,
You can use following:
Additional articles related to it:
https://www.fortiguard.com/services/ipge
Hello @SecurityPlus ,
This depends on how and where you have placed your restriction.
If you are talking bout host restrictions to connect to SSL VPN, below link contains the cli references for this and you can also see the group in GUI.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Restricting-allowing-sslvpn-access-from-sp...
If you have a local in policy, retrieve the group name from
conf firewall localin policy
edit <localin id>
set srcaddr "<Group name>"
exit
config firewall addrgrp
edit <Group name>
show
and copy the output.
Or, you could setup IPsec VPN, and don't bother about the Geo-blocking.. ;)
FortiGate: VPN: IPsec Wizzard....
To list all country names, you just need to hit '?' to see all options in the country address object you must have already.
config firewall address
edit "UnitedStates"
set type geography
set country ?
It would show like below:
fg40f-utm (UnitedStates) # set country ?
ZZ Reserved
O1 Other Country
AD Andorra
AE United Arab Emirates
AF Afghanistan
AG Antigua and Barbuda
AI Anguilla
AL Albania
AM Armenia
AN Netherlands Antilles
AO Angola
AQ Antarctica
AR Argentina
AS American Samoa
AT Austria
AU Australia
AW Aruba
AX Aland Islands
AZ Azerbaijan
BA Bosnia and Herzegovina
BB Barbados
BD Bangladesh
BE Belgium
BF Burkina Faso
BG Bulgaria
BH Bahrain
<snip>
Toshi
User | Count |
---|---|
2675 | |
1410 | |
810 | |
702 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.