Skip to content
Notifications
Clear all

How do I set up geo-fencing to block traffic from specific regions?

1 Posts
1 Users
0 Reactions
2 Views
(@emilyh)
Eminent Member
Joined: 5 days ago
Posts: 20
Topic starter   [#19934]

I've been exploring FortiSASE for a few weeks now, primarily to secure a small team of remote developers. I'm coming from a more traditional firewall background, so the SASE model is still new to me.

One requirement I have is to block all traffic originating from a couple of specific high-risk regions, regardless of user or application. I understand this is often called geo-fencing or geo-blocking. I've looked through the FortiSASE admin portal and the documentation, but I'm having trouble finding the exact workflow.

Could someone walk me through the steps to create this kind of policy? I'm particularly unsure about:
* Where the geo-IP controls are located (Security, Web Filtering, or its own section?).
* Whether I need to create an address object based on geography first, or if it's a direct condition in a policy.
* If this works for both web traffic and explicit proxy traffic, or if they are configured separately.

Any pointers to the right menu path or a basic configuration example would be really helpful. I'm trying to avoid having to create a long list of individual country-based IP ranges manually.



   
Quote