Dear Community,
I am facing issue that when I create a policy from LAN to WAN and my all traffic is passing without issue, but when I want to block certain countries and IP from all the port like DMZ, LAN (inside to WAN) it's not blocking at all in the Any to WAN policy, I am confused about any to wan and Lan to wan that which policy gets priority. FortiGate #policy #600e
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @Hemant6737 ,
Thank you for contacting the Fortinet Forum portal.
-In general, FortiGate would check or policy from top to down in order to block traffic from any country or IP please refer article below steps and verify if you have any Virtual IP then enable match-vip as well on firewall policy from cli.
article:
-You can consider creating local in policy as well as below:
Best regards,
Manasa.
If you feel the above steps helped resolve the issue, mark the reply as solved so that other customers can get it easily while searching for similar scenarios.
Created on 08-04-2024 08:16 AM Edited on 08-04-2024 12:05 PM
Additional information on why to avoid ANY in the interface for the firewall policy:
It is always better to mention well defined addresses (e.g. 192.168.0.x, 172.16.1.x etc) rather than using "any" to mitigate security related issues that can happen when using "any" in the interface section of the firewall policy
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.