Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tonyk
New Contributor II

Website Blocking question (FGT60F)

I'm a newbie regarding Fortinet products, so forgive me if I ask something silly  :)

 

When I hit an innocuous website like
www.newsweekjapan.jp

I get fortinic firewall notification that access was blocked by firewall policy 15.

I then check policy ID 15
It's named GEOBLOCK
It has for destinations two address groups
'GEO IP FILTER'
and
'BLOCKED-IPs-Group'

The first group does contain "Japan" (why it would is a mystery to med at the moment)

The 2nd does not contain the ip address (block) of Newsweekjapan

So yeah.. Seems all Japan ip/sites are blocked right?

Yet random *.jp sites I tried in chrome come up just fine

I found no exceptions that would seem to allow some jp sites through but not others

Confused 

 

1 Solution
abarushka
Staff
Staff

Hello,

 

It is possible verify on FortiGate side to which country certain IP address belongs to (i.e. diagnose geoip geoip-query <public ip>). Please find more details below:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Commands-to-verify-GeoIP-information-and/t...

FortiGate

View solution in original post

4 REPLIES 4
abarushka
Staff
Staff

Hello,

 

It is possible verify on FortiGate side to which country certain IP address belongs to (i.e. diagnose geoip geoip-query <public ip>). Please find more details below:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Commands-to-verify-GeoIP-information-and/t...

FortiGate
Tonyk
New Contributor II

Thank You for the reply. 
I will look at the link.info you shared!

Thanks again!

 

jackys
New Contributor

No worries, everyone starts somewhere! Understanding firewall policies and Fortinet products can be a bit overwhelming at first, but I'll try to help clarify the situation for you.

From what you described, it appears that Fortinet's firewall policy 15, named 'GEOBLOCK,' is designed to block access to certain destinations based on their geographic location. It uses two address groups: 'GEO IP FILTER' and 'BLOCKED-IPs-Group.' The 'GEO IP FILTER' group contains the "Japan" entry, which means it's blocking access to websites originating from Japan.

The reason you see a block message when trying to access newsweekjapan.jp is that it falls under the "Japan" category and is blocked by the firewall policy 15.

waqar11
New Contributor

The Fortinet firewall policy is blocking access to some *.jp sites, including many other websites. Check the firewall policy settings for misconfigurations, conflicting policies, and exceptions. Ensure the website is correctly categorized and consider testing with different browsers. If the issue persists, seek assistance from Fortinet support or their community forums.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors