Thanks for keeping it clean and simple. Appreciate it.
@oliverk.74223 жыл бұрын
Thank your for the script! I was close to adding it all from the Gui. Coming from a Sophos UTM where you have a convenient GUI page with all countries listed and you just need to click 'select all' I was shocked how Fortinet implemented geoblocking.
@thegoodguy554111 ай бұрын
GODS WORK!!!! Thank you soo much.
@SeanLongoria-p9nАй бұрын
So much help! Thanks!
@marcf96352 жыл бұрын
Thanks useful info in todays climate!
@coreybrown88644 жыл бұрын
Great video. Keep up the good work.
@marliearellano29784 жыл бұрын
Awesome vid!🙂
@workskirv10 ай бұрын
Informative and easy to follow
@gingerbadger2 жыл бұрын
Nice! Thank you. Was missing match- vip
@TechSoul4U5 ай бұрын
Great video... to the point. thanks
@chrischilds286815 күн бұрын
Doesn't setting trusted hosts essentially do the same thing and in a much less complex way? We have all our Fortigates locked down to just our WAN IP and the local data subnet for admin access.
@michaelschultz94543 жыл бұрын
Thanks for this script. It was looking like I was going to need to make one myself but I figured this has to be a common enough need that someone would have created it already. Honestly it's kind of dumb the way Fortinet executes this feature, and they should just add this script to the KBs or make a better way.
@jaredcarmouche40463 жыл бұрын
Felt the same way... Bit the bullet and did it myself lol
@thegoodguy554111 ай бұрын
@@jaredcarmouche4046 Heartfelt thank you
@dtcoleman053 жыл бұрын
Great!! However, do you have an example for only allowing Unites states IPs on specific policy inbound using VIP? For instance, I have an IPv4 policy (VIP) established that no other country should be hitting, only the US. Should I just change "Source"- from all to the United States? Then in cli set match-vip enable on that particular VIP policy?
@ruhirezaie79472 жыл бұрын
Yes, changing the 'source' from 'all' to United States will do the job. But 'set match-vip enable' doesn't work for Accept policies, it only works on Deny policies.
@blaketomlinson39158 ай бұрын
dude thank you so much!
@TheQuadrider214 жыл бұрын
Thank you, I was missing the Match-vip enable in policy and was wondering why there were no logs... Per the local in policy, we only allow FMG-Access and Ping on our Wan ports, but we do have SSLVPN turned on. Does the local in alow filter for the SSL users? or only the WAN ports?
@jaredcarmouche40464 жыл бұрын
That's a great question, I think you can apply it to the ssl vpn interface as well.
@hafezelashry2275 Жыл бұрын
@@jaredcarmouche4046 I don't think this point because the virtual interface is sub interface from physical interface, if you have any info more please share with us about this point
@hafezelashry2275 Жыл бұрын
Great video
@cybersecprep60033 жыл бұрын
Excellent Video.
@sammahajan5662 жыл бұрын
very cool video...any thought of using the negate option (so basically you create a rule that says any traffic NOT from the US, block....?
@mnsb1662 жыл бұрын
Big Thanks to you bro...
@Iv4nTech2 жыл бұрын
thus Geolocation work on inbound policy who had natted public IP?
@quick-updatetv46754 жыл бұрын
does VPN client affected on this setup? just curios if ill be in china and I want to access my internal files in US since all are block should VPN Client be also affected..
@urvhalt2 жыл бұрын
Is there the possibility to drop ( drop on floor ) instead of deny? Denial usually means to send a packet back..
@piratarebel2 жыл бұрын
sorry I have a doubt, what is the difference blocking IP address by firewall policy than blocking it by local in policy?
@ruhirezaie79472 жыл бұрын
Local-in firewall policy is when the attackers want to access your administrative interface (HTTPS, HTTP, SSH etc.), like when they want to login to your firewall administratively.
@denisstpierre71404 жыл бұрын
Question. If we wanted to allow only for instance Canada. Could we configure Canada as an address and accept only that one. Using Negate Source?
@HRCFan3 жыл бұрын
Yes, but then another policy after to deny all other countries.
@sachivmehra5372 жыл бұрын
Hi - the set match-vip enable looks to be deprecated or not working on fortios 7.0? Any ideas?
@ruhirezaie79472 жыл бұрын
It works but only on Deny policies moving forward.
@fernandoaberguno96132 жыл бұрын
Thanks!!
@EJJackson4 жыл бұрын
Nice video...simple and easy to use. Suggestion....in the script you have can you make the Address not visible. The reason I ask is now I need to change the visibility on all the countries in the Address list. I'm always using the Group in Addresses, not the individual country name. I'm changing the country visibility manually. Maybe you have a suggestion for changing the visibility in bulk
@jaredcarmouche40464 жыл бұрын
Great suggestion, I'm pretty sure I can just copy paste the command for that in the script.
@jaredcarmouche40464 жыл бұрын
Taking a closer look, all you would have to do is add this line to every address entry: set visibility disable