Fortigate Country Blocking | Geo Blocking | Local In Policy Setup + Script!

  Рет қаралды 22,222

Jared Carmouche

Jared Carmouche

Күн бұрын

Пікірлер: 39
@doghousemine
@doghousemine Жыл бұрын
Thanks for keeping it clean and simple. Appreciate it.
@oliverk.7422
@oliverk.7422 3 жыл бұрын
Thank your for the script! I was close to adding it all from the Gui. Coming from a Sophos UTM where you have a convenient GUI page with all countries listed and you just need to click 'select all' I was shocked how Fortinet implemented geoblocking.
@thegoodguy5541
@thegoodguy5541 11 ай бұрын
GODS WORK!!!! Thank you soo much.
@SeanLongoria-p9n
@SeanLongoria-p9n Ай бұрын
So much help! Thanks!
@marcf9635
@marcf9635 2 жыл бұрын
Thanks useful info in todays climate!
@coreybrown8864
@coreybrown8864 4 жыл бұрын
Great video. Keep up the good work.
@marliearellano2978
@marliearellano2978 4 жыл бұрын
Awesome vid!🙂
@workskirv
@workskirv 10 ай бұрын
Informative and easy to follow
@gingerbadger
@gingerbadger 2 жыл бұрын
Nice! Thank you. Was missing match- vip
@TechSoul4U
@TechSoul4U 5 ай бұрын
Great video... to the point. thanks
@chrischilds2868
@chrischilds2868 15 күн бұрын
Doesn't setting trusted hosts essentially do the same thing and in a much less complex way? We have all our Fortigates locked down to just our WAN IP and the local data subnet for admin access.
@michaelschultz9454
@michaelschultz9454 3 жыл бұрын
Thanks for this script. It was looking like I was going to need to make one myself but I figured this has to be a common enough need that someone would have created it already. Honestly it's kind of dumb the way Fortinet executes this feature, and they should just add this script to the KBs or make a better way.
@jaredcarmouche4046
@jaredcarmouche4046 3 жыл бұрын
Felt the same way... Bit the bullet and did it myself lol
@thegoodguy5541
@thegoodguy5541 11 ай бұрын
@@jaredcarmouche4046 Heartfelt thank you
@dtcoleman05
@dtcoleman05 3 жыл бұрын
Great!! However, do you have an example for only allowing Unites states IPs on specific policy inbound using VIP? For instance, I have an IPv4 policy (VIP) established that no other country should be hitting, only the US. Should I just change "Source"- from all to the United States? Then in cli set match-vip enable on that particular VIP policy?
@ruhirezaie7947
@ruhirezaie7947 2 жыл бұрын
Yes, changing the 'source' from 'all' to United States will do the job. But 'set match-vip enable' doesn't work for Accept policies, it only works on Deny policies.
@blaketomlinson3915
@blaketomlinson3915 8 ай бұрын
dude thank you so much!
@TheQuadrider21
@TheQuadrider21 4 жыл бұрын
Thank you, I was missing the Match-vip enable in policy and was wondering why there were no logs... Per the local in policy, we only allow FMG-Access and Ping on our Wan ports, but we do have SSLVPN turned on. Does the local in alow filter for the SSL users? or only the WAN ports?
@jaredcarmouche4046
@jaredcarmouche4046 4 жыл бұрын
That's a great question, I think you can apply it to the ssl vpn interface as well.
@hafezelashry2275
@hafezelashry2275 Жыл бұрын
​@@jaredcarmouche4046 I don't think this point because the virtual interface is sub interface from physical interface, if you have any info more please share with us about this point
@hafezelashry2275
@hafezelashry2275 Жыл бұрын
Great video
@cybersecprep6003
@cybersecprep6003 3 жыл бұрын
Excellent Video.
@sammahajan566
@sammahajan566 2 жыл бұрын
very cool video...any thought of using the negate option (so basically you create a rule that says any traffic NOT from the US, block....?
@mnsb166
@mnsb166 2 жыл бұрын
Big Thanks to you bro...
@Iv4nTech
@Iv4nTech 2 жыл бұрын
thus Geolocation work on inbound policy who had natted public IP?
@quick-updatetv4675
@quick-updatetv4675 4 жыл бұрын
does VPN client affected on this setup? just curios if ill be in china and I want to access my internal files in US since all are block should VPN Client be also affected..
@urvhalt
@urvhalt 2 жыл бұрын
Is there the possibility to drop ( drop on floor ) instead of deny? Denial usually means to send a packet back..
@piratarebel
@piratarebel 2 жыл бұрын
sorry I have a doubt, what is the difference blocking IP address by firewall policy than blocking it by local in policy?
@ruhirezaie7947
@ruhirezaie7947 2 жыл бұрын
Local-in firewall policy is when the attackers want to access your administrative interface (HTTPS, HTTP, SSH etc.), like when they want to login to your firewall administratively.
@denisstpierre7140
@denisstpierre7140 4 жыл бұрын
Question. If we wanted to allow only for instance Canada. Could we configure Canada as an address and accept only that one. Using Negate Source?
@HRCFan
@HRCFan 3 жыл бұрын
Yes, but then another policy after to deny all other countries.
@sachivmehra537
@sachivmehra537 2 жыл бұрын
Hi - the set match-vip enable looks to be deprecated or not working on fortios 7.0? Any ideas?
@ruhirezaie7947
@ruhirezaie7947 2 жыл бұрын
It works but only on Deny policies moving forward.
@fernandoaberguno9613
@fernandoaberguno9613 2 жыл бұрын
Thanks!!
@EJJackson
@EJJackson 4 жыл бұрын
Nice video...simple and easy to use. Suggestion....in the script you have can you make the Address not visible. The reason I ask is now I need to change the visibility on all the countries in the Address list. I'm always using the Group in Addresses, not the individual country name. I'm changing the country visibility manually. Maybe you have a suggestion for changing the visibility in bulk
@jaredcarmouche4046
@jaredcarmouche4046 4 жыл бұрын
Great suggestion, I'm pretty sure I can just copy paste the command for that in the script.
@jaredcarmouche4046
@jaredcarmouche4046 4 жыл бұрын
Taking a closer look, all you would have to do is add this line to every address entry: set visibility disable
@VijayKumar-tk9ym
@VijayKumar-tk9ym 4 жыл бұрын
Thank you
@angelical791
@angelical791 4 жыл бұрын
Thank you, Great video. Script ?
Арыстанның айқасы, Тәуіржанның шайқасы!
25:51
QosLike / ҚосЛайк / Косылайық
Рет қаралды 639 М.
I thought one thing and the truth is something else 😂
00:34
عائلة ابو رعد Abo Raad family
Рет қаралды 22 МЛН
If people acted like cats 🙀😹 LeoNata family #shorts
00:22
LeoNata Family
Рет қаралды 41 МЛН
GEO BLOCKING THE RIGHT WAY!!!
7:52
Forti Tip
Рет қаралды 12 М.
Fortigate DNS Server - Set up a DNS Server on your Fortigate Firewall
6:58
«Если 50 детей не рожу - ничего не добился»
1:26:17
Full Fortinet Stack Environment
27:39
Fortinet Guru
Рет қаралды 69 М.
Trolling Hackers with a Honeypot and how you can too
20:08
Gnar Coding
Рет қаралды 4,1 М.