Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Badger_89
New Contributor III

Geo-blocking Plan

Hi

 

I have the below requirement just looking for thoughts on the best way to do it....I need to do outbound blocking only for now.

 

The site has a /16 assigned to it, carved up into many small subnets.....Most of the subnets will have the same banned countries, however, there are 3 subnets (scattered all round the /16) that require no restrictions.

 

What is the cleanest way to tackle this? Couple of options that came to mind are

 

1. Create an address group for the /16, and use address exclude for the 3 subnets. Then in the rule block access to the restricted countries. Never used this feature before but it seems appropriate here.

 

2. Do the internet rules for the 3 VLAN's first, then block the countries for the rest, then do the normal rules for the rest

 

any other ideas?

 

thanks

 

 

3 Solutions
Toshi_Esumi
SuperUser
SuperUser

Definitely No.2 is better. Especially, when you need to add more to the exceptions.

Toshi

View solution in original post

dingjerry_FTNT

Hi @Badger_89 ,

 

Option #2 is much easier.

Regards,

Jerry

View solution in original post

Theo4
New Contributor II

I would also go with number 2. Easier and clearer for others managing the same firewall

View solution in original post

4 REPLIES 4
Toshi_Esumi
SuperUser
SuperUser

Definitely No.2 is better. Especially, when you need to add more to the exceptions.

Toshi

dingjerry_FTNT

Hi @Badger_89 ,

 

Option #2 is much easier.

Regards,

Jerry
Theo4
New Contributor II

I would also go with number 2. Easier and clearer for others managing the same firewall

Badger_89
New Contributor III

thanks for the feedback, will go option 2

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors