Dear All,
Can anyone tell us how many IP can we block on particular policy for instance -
Lets suppose we have created one policy on fortigate firewall and I want to block one by one ip so how many IP can we block and is there any limitation on firewall policy.
Actually the thing is that we have to block around 10000 IP on fortigate firewall.
Regards,
Umesh Prajapati
Hello Umesh,
Blocking IPs in a policy one by one is probably not the best approach to... anything that has more than 20-30IPs.
You can use DDoS, GeoIP to block by country, external resources to store these IPs as a file on an external server, or use trusted hosts for admin users managing the unit.
The public IPs that are showing attacks are too many to block like this, and changing too often to be worth the effort of setting up such policy, and also an effort to maintain it trough the GUI.
However, there is no limit to the number of objects in the policy, but there is a limit of the total address objects in the FortiGate (version dependant):
https://docs.fortinet.com/max-value-table
(select your unit and firmware version, and search for firewall.address)
Just keep it in mind that if you want to block access to your FGT, like VPNs, HTTPS, SSH, etc., you need to use local-in policy instead. Regular policies are for coming through traffic, from one interface to another interface.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.