- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Geo-blocking Plan
Hi
I have the below requirement just looking for thoughts on the best way to do it....I need to do outbound blocking only for now.
The site has a /16 assigned to it, carved up into many small subnets.....Most of the subnets will have the same banned countries, however, there are 3 subnets (scattered all round the /16) that require no restrictions.
What is the cleanest way to tackle this? Couple of options that came to mind are
1. Create an address group for the /16, and use address exclude for the 3 subnets. Then in the rule block access to the restricted countries. Never used this feature before but it seems appropriate here.
2. Do the internet rules for the 3 VLAN's first, then block the countries for the rest, then do the normal rules for the rest
any other ideas?
thanks
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Definitely No.2 is better. Especially, when you need to add more to the exceptions.
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would also go with number 2. Easier and clearer for others managing the same firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Definitely No.2 is better. Especially, when you need to add more to the exceptions.
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would also go with number 2. Easier and clearer for others managing the same firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks for the feedback, will go option 2
