Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
yuranilg
New Contributor II

Lock with acl on Fortigate 50E

I need to block the traffic to my FTG by geographic IP. However, the 50E models do not have this ACL option, how can I do it?
1 Solution
kgeorge
Staff
Staff

Hello @yuranilg,

 

 

Only 

The following platforms/models support ACL:

  • FGT_100D, FGT_100E, FGT_100EF, FGT_101E.
  • FGT_140D, FGT_140D_POE, FGT_140E, FGT_140E_POE.
  • FGT_301E, FGT_500E, FGT_501E.
  • FGT_1200D, FGT_1500D, FGT_1500DT.
  • FGT_2000E, FGT_2500E.
  • FGT_3000D, FGT_3100D, FGT_3200D, FGT_3700D.
  • FGT_3800D, FGT_3810D, FGT_3815D.
  • FGT_3960E, FGT_3980E.

The closest alternative for this would be Local-in-policy and here is the documentation for the same,

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/363127/local-in-policies

 

Regards,
Klint George

View solution in original post

2 REPLIES 2
kgeorge
Staff
Staff

Hello @yuranilg,

 

 

Only 

The following platforms/models support ACL:

  • FGT_100D, FGT_100E, FGT_100EF, FGT_101E.
  • FGT_140D, FGT_140D_POE, FGT_140E, FGT_140E_POE.
  • FGT_301E, FGT_500E, FGT_501E.
  • FGT_1200D, FGT_1500D, FGT_1500DT.
  • FGT_2000E, FGT_2500E.
  • FGT_3000D, FGT_3100D, FGT_3200D, FGT_3700D.
  • FGT_3800D, FGT_3810D, FGT_3815D.
  • FGT_3960E, FGT_3980E.

The closest alternative for this would be Local-in-policy and here is the documentation for the same,

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/363127/local-in-policies

 

Regards,
Klint George
chauhans
Staff
Staff

Hello @yuranilg 

As I understand that you want to block traffic by Geographic IP. You may also follow the below steps to achieve your requirement:

 

  1. Go to Policy & Objects > Addresses > Create New.

  2. In the Name field, enter a name for the geographic IP address object.

  3. In the Type field, select Geography.

  4. In the Country field, select the country that you want to block traffic from.

  5. Click OK.

  6. Go to Policy & Objects > Firewall Policies > Create New.

  7. In the Name field, enter a name for the firewall policy.

  8. In the Source field, select the geographic IP address object that you created in the previous step.

  9. In the Destination field, select the network or device that you want to protect.

  10. In the Action field, select Deny.

  11. Click OK.

Once you have created the geographic IP address object and the firewall policy, traffic from the specified country will be blocked.

Thanks,
Shaleni

 

Labels
Top Kudoed Authors