Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BNDP
New Contributor

Unwanted traffic on outgoing policy with FG-300C FW with 5.2.11 V

Hi,

 

I am facing the issue with the unwanted traffic from different countries are accepting on my outgoing policy.

Actually I have restricted the traffic from only specific countries but beyond that traffic is generating.

 

Whenever I am clearing the sessions of that certain specific IP's next 10 to 15 min the traffic is getting denied.

 

But again after that 20 min time period, unwanted traffic is generating.

 

Please help with this.

2 REPLIES 2
Dave_Hall
Honored Contributor

Create Geography-based address labels then group them into a list of countries you want blocked.  Then:

1. create a firewall policy from inside (e.g. lan) going out (e..g. WAN1) using the "block countries" group as the dest address.  Move this policy to the top of the firewall chain.

2. For blocking unwanted traffic from countries in the reverse direction (or from hitting the fgt's public IP address) - enable Local-In policies then (in the CLI) create a Local-In policy that blocks the "block countries" group (source).

 

Number #2 above is tricky if you have servers running internally that need to (receive) communications from other countries. (e.g. mail server).

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
emnoc
Esteemed Contributor III

 Actually I have restricted the traffic from only specific countries but beyond that traffic is generating.  

 

I would 1st have him look at his policy(s). If the policy is matching and then not matching or vice-versa than the traffic is changing or the policy is not correct. 

 

Is either correct or not-correct. He can adjust the policy to meet his needs.

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors