Technical Tip: How to block specific external (public) IP address via IPv4 policy

Technical Tip: How to block specific external (public) IP address via IPv4 policy


This article explains how to block some of the specific public IP address to enter the internal network of the FortiGate to protect the internal network.


Step1: Create an address object

Go to Policy & Objects -> Addresses
Click on ‘create new’ and ‘Address’

Category: Address
Name: Provide any name
Type: Subnet
Subnet / IP Range :   x.x.x.x/32   where x.x.x.x is the  specific public IP it is required to block
                                  x.x.x.x/24   where x.x.x.x is the subnet it is required to block and /24 is the subnet

Interface: Any
Click on ‘OK’ to apply the changes Step2: Create IPv4 Policy

Go to Policy & Objects -> IPv4 policy
Click on ‘create new ‘
Name: Provide any name
Incoming interface: WAN interface
Outgoing interface: LAN interface
Source: Select the address object, created above.
Destination: set it to “all”
Schedule: Always
Services: All
Action: Deny
NAT: Enable
Security Profiles:
Enable IPS
 Click on ‘OK’ and place this policy to the top of the IPv4 policy list (by drag and drop) from the ID column. 

Leave a Reply

Your email address will not be published. Required fields are marked *



Để cấu hình Config Archive, các bạn vào mode config và kích hoạt bằng lệnh archive. switch(config)#archiveswitch(config-archive)# Chúng ta sẽ có…

Schedule Auto Reboot Fortigate

DescriptionAll of the FortiOS firmware so far allow the user to program a daily restart (reboot) of the FortiGate, at…

Cách chặn gửi file qua Zalo (nhưng vẫn cho chát)

Ví dụ như zalo sẽ có 1 số server để chứa file khi người A gửi file cho người B,…

Hướng dẫn cấu hình Router Mikrotik

Router Mikrotik hiện được sử dụng rất nhiều ở Việt Nam (trong đó có cả các ISP) vì có giá…