Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
stsbrad
New Contributor

Country Blocking

Went searching as much as possible and couldn't find a solution so I made one myself. Thought I'd share to save someone else the legwork if they wanted to also do it. We want to block all incoming connections from any country outside the U.S. So Fortinet documentation says you have to create a firewall address object for each country you want to block. I use dual WAN's on each firewall so it was quite a bit of blah work.

 

Here are the address objects if anyone else wants to use them. Just throw them all into a group and block away if needed.

 

config firewall address

edit "Afghanistan - WAN1" set type geography set associated-interface "wan1" set country "AF" next edit "Aland Islands - WAN1" set type geography set associated-interface "wan1" set country "AX" next edit "Albania - WAN1" set type geography set associated-interface "wan1" set country "AL" next edit "Algeria - WAN1" set type geography set associated-interface "wan1" set country "DZ" next edit "American Samoa - WAN1" set type geography set associated-interface "wan1" set country "AS" next edit "Andorra - WAN1" set type geography set associated-interface "wan1" set country "AD" next edit "Angola - WAN1" set type geography set associated-interface "wan1" set country "AO" next edit "Anguilla - WAN1" set type geography set associated-interface "wan1" set country "AI" next edit "Antartica - WAN1" set type geography set associated-interface "wan1" set country "AQ" next edit "Antigua and Barbuda - WAN1" set type geography set associated-interface "wan1" set country "AG" next edit "Argentina - WAN1" set type geography set associated-interface "wan1" set country "AR" next edit "Armenia - WAN1" set type geography set associated-interface "wan1" set country "AM" next edit "Aruba - WAN1" set type geography set associated-interface "wan1" set country "AW" next edit "Australia - WAN1" set type geography set associated-interface "wan1" set country "AU" next edit "Austria - WAN1" set type geography set associated-interface "wan1" set country "AT" next edit "Azerbaijan - WAN1" set type geography set associated-interface "wan1" set country "AZ" next edit "Bahamas - WAN1" set type geography set associated-interface "wan1" set country "BS" next edit "Bahrain - WAN1" set type geography set associated-interface "wan1" set country "BH" next edit "Bangladesh - WAN1" set type geography set associated-interface "wan1" set country "BD" next edit "Barbados - WAN1" set type geography set associated-interface "wan1" set country "BB" next edit "Belarus - WAN1" set type geography set associated-interface "wan1" set country "BY" next edit "Belgium - WAN1" set type geography set associated-interface "wan1" set country "BE" next edit "Belize - WAN1" set type geography set associated-interface "wan1" set country "BZ" next edit "Benin - WAN1" set type geography set associated-interface "wan1" set country "BJ" next edit "Bermuda - WAN1" set type geography set associated-interface "wan1" set country "BM" next edit "Bhutan - WAN1" set type geography set associated-interface "wan1" set country "BT" next edit "Bolivia - WAN1" set type geography set associated-interface "wan1" set country "BO" next edit "Bonaire, Saint Eustatius and Saba - WAN1" set type geography set associated-interface "wan1" set country "BQ" next edit "Bosnia and Herzegovina - WAN1" set type geography set associated-interface "wan1" set country "BA" next edit "Botswana - WAN1" set type geography set associated-interface "wan1" set country "BW" next edit "Bouvet Island - WAN1" set type geography set associated-interface "wan1" set country "BV" next edit "Brazil - WAN1" set type geography set associated-interface "wan1" set country "BR" next edit "British Indian Ocean Territory - WAN1" set type geography set associated-interface "wan1" set country "IO" next edit "Brunei Darussalam - WAN1" set type geography set associated-interface "wan1" set country "BN" next edit "Bulgaria - WAN1" set type geography set associated-interface "wan1" set country "BG" next edit "Burkina Faso - WAN1" set type geography set associated-interface "wan1" set country "BF" next edit "Burundi - WAN1" set type geography set associated-interface "wan1" set country "BI" next edit "Cambodia - WAN1" set type geography set associated-interface "wan1" set country "KH" next edit "Cameroon - WAN1" set type geography set associated-interface "wan1" set country "CM" next edit "Canada - WAN1" set type geography set associated-interface "wan1" set country "CA" next edit "Cape Verde - WAN1" set type geography set associated-interface "wan1" set country "CV" next edit "Cayman Islands Central African Republic - WAN1" set type geography set associated-interface "wan1" set country "" next edit "Chad - WAN1" set type geography set associated-interface "wan1" set country "TD" next edit "Chile - WAN1" set type geography set associated-interface "wan1" set country "CL" next edit "China - WAN1" set type geography set associated-interface "wan1" set country "CN" next edit "Christmas Island - WAN1" set type geography set associated-interface "wan1" set country "KY" next edit "Cocos (Keeling) Islands - WAN1" set type geography set associated-interface "wan1" set country "CC" next edit "Colombia - WAN1" set type geography set associated-interface "wan1" set country "CO" next edit "Comoros - WAN1" set type geography set associated-interface "wan1" set country "KM" next edit "Congo - WAN1" set type geography set associated-interface "wan1" set country "CG" next edit "Congo, The Democratic Republic of the - WAN1" set type geography set associated-interface "wan1" set country "CD" next edit "Cook Islands - WAN1" set type geography set associated-interface "wan1" set country "CK" next edit "Costa Rica - WAN1" set type geography set associated-interface "wan1" set country "CR" next edit "Cote d'Ivoire - WAN1" set type geography set associated-interface "wan1" set country "CI" next edit "Croatia - WAN1" set type geography set associated-interface "wan1" set country "HR" next edit "Cuba - WAN1" set type geography set associated-interface "wan1" set country "CU" next edit "Curacao - WAN1" set type geography set associated-interface "wan1" set country "CW" next edit "Cyprus - WAN1" set type geography set associated-interface "wan1" set country "CY" next edit "Czech Republic - WAN1" set type geography set associated-interface "wan1" set country "CZ" next edit "Denmark - WAN1" set type geography set associated-interface "wan1" set country "DK" next edit "Djibouti - WAN1" set type geography set associated-interface "wan1" set country "DJ" next edit "Dominica - WAN1" set type geography set associated-interface "wan1" set country "DM" next edit "Dominican Republic - WAN1" set type geography set associated-interface "wan1" set country "DO" next edit "Ecuador - WAN1" set type geography set associated-interface "wan1" set country "EC" next edit "Egypt - WAN1" set type geography set associated-interface "wan1" set country "EG" next edit "El Salvador - WAN1" set type geography set associated-interface "wan1" set country "SV" next edit "Equatorial Guinea - WAN1" set type geography set associated-interface "wan1" set country "GQ" next edit "Eritrea - WAN1" set type geography set associated-interface "wan1" set country "ER" next edit "Estonia - WAN1" set type geography set associated-interface "wan1" set country "EE" next edit "Ethiopia - WAN1" set type geography set associated-interface "wan1" set country "ET" next edit "Falkland Islands (Malvinas) - WAN1" set type geography set associated-interface "wan1" set country "FK" next edit "Faroe Islands - WAN1" set type geography set associated-interface "wan1" set country "FO" next edit "Fiji - WAN1" set type geography set associated-interface "wan1" set country "FJ" next edit "Finland - WAN1" set type geography set associated-interface "wan1" set country "FI" next edit "France - WAN1" set type geography set associated-interface "wan1" set country "FR" next edit "French Guiana - WAN1" set type geography set associated-interface "wan1" set country "GF" next edit "French Polynesia - WAN1" set type geography set associated-interface "wan1" set country "PF" next edit "French Southern Territories - WAN1" set type geography set associated-interface "wan1" set country "TF" next edit "Gabon - WAN1" set type geography set associated-interface "wan1" set country "GA" next edit "Gambia - WAN1" set type geography set associated-interface "wan1" set country "GM" next edit "Georgia - WAN1" set type geography set associated-interface "wan1" set country "GE" next edit "Germany - WAN1" set type geography set associated-interface "wan1" set country "DE" next edit "Ghana - WAN1" set type geography set associated-interface "wan1" set country "GH" next edit "Gibraltar - WAN1" set type geography set associated-interface "wan1" set country "GI" next edit "Greece - WAN1" set type geography set associated-interface "wan1" set country "GR" next edit "Greenland - WAN1" set type geography set associated-interface "wan1" set country "GL" next edit "Grenada - WAN1" set type geography set associated-interface "wan1" set country "GD" next edit "Guadeloupe - WAN1" set type geography set associated-interface "wan1" set country "GP" next edit "Guam - WAN1" set type geography set associated-interface "wan1" set country "GU" next edit "Guatemala - WAN1" set type geography set associated-interface "wan1" set country "GT" next edit "Guernsey - WAN1" set type geography set associated-interface "wan1" set country "GG" next edit "Guinea - WAN1" set type geography set associated-interface "wan1" set country "GN" next edit "Guinea-Bissau - WAN1" set type geography set associated-interface "wan1" set country "GW" next edit "Guyana - WAN1" set type geography set associated-interface "wan1" set country "GY" next edit "Haiti - WAN1" set type geography set associated-interface "wan1" set country "HT" next edit "Heard Island and Mcdonald Islands - WAN1" set type geography set associated-interface "wan1" set country "HM" next edit "Holy See (Vatican City State) - WAN1" set type geography set associated-interface "wan1" set country "VA" next edit "Honduras - WAN1" set type geography set associated-interface "wan1" set country "HN" next edit "Hong Kong - WAN1" set type geography set associated-interface "wan1" set country "HK" next edit "Hungary - WAN1" set type geography set associated-interface "wan1" set country "HU" next edit "Iceland - WAN1" set type geography set associated-interface "wan1" set country "IS" next edit "India - WAN1" set type geography set associated-interface "wan1" set country "IN" next edit "Indonesia - WAN1" set type geography set associated-interface "wan1" set country "ID" next edit "Iran, Islamic Republic of - WAN1" set type geography set associated-interface "wan1" set country "IR" next edit "Iraq - WAN1" set type geography set associated-interface "wan1" set country "IQ" next edit "Ireland - WAN1" set type geography set associated-interface "wan1" set country "IE" next edit "Isle of Man - WAN1" set type geography set associated-interface "wan1" set country "IM" next edit "Israel - WAN1" set type geography set associated-interface "wan1" set country "IL" next edit "Italy - WAN1" set type geography set associated-interface "wan1" set country "IT" next edit "Jamaica - WAN1" set type geography set associated-interface "wan1" set country "JM" next edit "Japan - WAN1" set type geography set associated-interface "wan1" set country "JP" next edit "Jersey - WAN1" set type geography set associated-interface "wan1" set country "JE" next edit "Jordan - WAN1" set type geography set associated-interface "wan1" set country "JO" next edit "Kazakhstan - WAN1" set type geography set associated-interface "wan1" set country "KZ" next edit "Kenya - WAN1" set type geography set associated-interface "wan1" set country "KE" next edit "Kiribati - WAN1" set type geography set associated-interface "wan1" set country "KI" next edit "North Korea - WAN1" set type geography set associated-interface "wan1" set country "KP" next edit "South Korea - WAN1" set type geography set associated-interface "wan1" set country "KR" next edit "Kosovo - WAN1" set type geography set associated-interface "wan1" set country "XK" next edit "Kuwait - WAN1" set type geography set associated-interface "wan1" set country "KW" next edit "Kyrgyzstan - WAN1" set type geography set associated-interface "wan1" set country "KG" next edit "Lao People's Democratic Republic - WAN1" set type geography set associated-interface "wan1" set country "LA" next edit "Latvia - WAN1" set type geography set associated-interface "wan1" set country "LV" next edit "Lebanon - WAN1" set type geography set associated-interface "wan1" set country "LB" next edit "Lesotho - WAN1" set type geography set associated-interface "wan1" set country "LS" next edit "Liberia - WAN1" set type geography set associated-interface "wan1" set country "LR" next edit "Libya - WAN1" set type geography set associated-interface "wan1" set country "LY" next edit "Liechtenstein - WAN1" set type geography set associated-interface "wan1" set country "LI" next edit "Lithuania - WAN1" set type geography set associated-interface "wan1" set country "LT" next edit "Luxembourg - WAN1" set type geography set associated-interface "wan1" set country "LU" next edit "Macao - WAN1" set type geography set associated-interface "wan1" set country "MO" next edit "Macedonia - WAN1" set type geography set associated-interface "wan1" set country "MK" next edit "Madagascar - WAN1" set type geography set associated-interface "wan1" set country "MG" next edit "Malawi - WAN1" set type geography set associated-interface "wan1" set country "MW" next edit "Malaysia - WAN1" set type geography set associated-interface "wan1" set country "MY" next edit "Maldives - WAN1" set type geography set associated-interface "wan1" set country "MV" next edit "Mali - WAN1" set type geography set associated-interface "wan1" set country "ML" next edit "Malta - WAN1" set type geography set associated-interface "wan1" set country "MT" next edit "Marshall Islands - WAN1" set type geography set associated-interface "wan1" set country "MH" next edit "Martinique - WAN1" set type geography set associated-interface "wan1" set country "MQ" next edit "Mauritania - WAN1" set type geography set associated-interface "wan1" set country "MR" next edit "Mauritius - WAN1" set type geography set associated-interface "wan1" set country "MU" next edit "Mayotte - WAN1" set type geography set associated-interface "wan1" set country "YT" next edit "Mexico - WAN1" set type geography set associated-interface "wan1" set country "MX" next edit "Micronesia, Federated States of - WAN1" set type geography set associated-interface "wan1" set country "FM" next edit "Moldova, Republic of - WAN1" set type geography set associated-interface "wan1" set country "MD" next edit "Monaco - WAN1" set type geography set associated-interface "wan1" set country "MC" next edit "Mongolia - WAN1" set type geography set associated-interface "wan1" set country "MN" next edit "Montenegro - WAN1" set type geography set associated-interface "wan1" set country "ME" next edit "Montserrat - WAN1" set type geography set associated-interface "wan1" set country "MS" next edit "Morocco - WAN1" set type geography set associated-interface "wan1" set country "MA" next edit "Mozambique - WAN1" set type geography set associated-interface "wan1" set country "MZ" next edit "Myanmar - WAN1" set type geography set associated-interface "wan1" set country "MM" next edit "Namibia - WAN1" set type geography set associated-interface "wan1" set country "NA" next edit "Nauru - WAN1" set type geography set associated-interface "wan1" set country "NR" next edit "Nepal - WAN1" set type geography set associated-interface "wan1" set country "NP" next edit "Netherlands - WAN1" set type geography set associated-interface "wan1" set country "NL" next edit "Netherlands Antilles - WAN1" set type geography set associated-interface "wan1" set country "AN" next edit "New Caledonia - WAN1" set type geography set associated-interface "wan1" set country "NC" next edit "New Zealand - WAN1" set type geography set associated-interface "wan1" set country "NZ" next edit "Nicaragua - WAN1" set type geography set associated-interface "wan1" set country "NI" next edit "Niger - WAN1" set type geography set associated-interface "wan1" set country "NE" next edit "Nigeria - WAN1" set type geography set associated-interface "wan1" set country "NG" next edit "Niue - WAN1" set type geography set associated-interface "wan1" set country "NU" next edit "Norfolk Island - WAN1" set type geography set associated-interface "wan1" set country "NF" next edit "Northern Mariana Islands - WAN1" set type geography set associated-interface "wan1" set country "MP" next edit "Norway - WAN1" set type geography set associated-interface "wan1" set country "NO" next edit "Oman - WAN1" set type geography set associated-interface "wan1" set country "OM" next edit "Pakistan - WAN1" set type geography set associated-interface "wan1" set country "PK" next edit "Palau - WAN1" set type geography set associated-interface "wan1" set country "PW" next edit "Palestinian Territory - WAN1" set type geography set associated-interface "wan1" set country "PS" next edit "Panama - WAN1" set type geography set associated-interface "wan1" set country "PA" next edit "Papua New Guinea - WAN1" set type geography set associated-interface "wan1" set country "PG" next edit "Paraguay - WAN1" set type geography set associated-interface "wan1" set country "PY" next edit "Peru - WAN1" set type geography set associated-interface "wan1" set country "PE" next edit "Philippines - WAN1" set type geography set associated-interface "wan1" set country "PH" next edit "Pitcairn - WAN1" set type geography set associated-interface "wan1" set country "PN" next edit "Poland - WAN1" set type geography set associated-interface "wan1" set country "PL" next edit "Portugal - WAN1" set type geography set associated-interface "wan1" set country "PT" next edit "Puerto Rico - WAN1" set type geography set associated-interface "wan1" set country "PR" next edit "Qatar - WAN1" set type geography set associated-interface "wan1" set country "QA" next edit "Romania - WAN1" set type geography set associated-interface "wan1" set country "RO" next edit "Russian Federation - WAN1" set type geography set associated-interface "wan1" set country "RU" next edit "Rwanda - WAN1" set type geography set associated-interface "wan1" set country "RW" next edit "Saint Bartelemey - WAN1" set type geography set associated-interface "wan1" set country "BL" next edit "Saint Helena - WAN1" set type geography set associated-interface "wan1" set country "SH" next edit "Saint Kitts and Nevis - WAN1" set type geography set associated-interface "wan1" set country "KN" next edit "Saint Lucia - WAN1" set type geography set associated-interface "wan1" set country "LC" next edit "Saint Martin - WAN1" set type geography set associated-interface "wan1" set country "MF" next edit "Saint Pierre and Miquelon - WAN1" set type geography set associated-interface "wan1" set country "PM" next edit "Saint Vincent and the Grenadines - WAN1" set type geography set associated-interface "wan1" set country "VC" next edit "Samoa - WAN1" set type geography set associated-interface "wan1" set country "WS" next edit "San Marino - WAN1" set type geography set associated-interface "wan1" set country "SM" next edit "Sao Tome and Principe - WAN1" set type geography set associated-interface "wan1" set country "ST" next edit "Saudi Arabia - WAN1" set type geography set associated-interface "wan1" set country "SA" next edit "Senegal - WAN1" set type geography set associated-interface "wan1" set country "SN" next edit "Serbia - WAN1" set type geography set associated-interface "wan1" set country "RS" next edit "Seychelles - WAN1" set type geography set associated-interface "wan1" set country "SC" next edit "Sierra Leone - WAN1" set type geography set associated-interface "wan1" set country "SL" next edit "Singapore - WAN1" set type geography set associated-interface "wan1" set country "SG" next edit "Sint Maarten - WAN1" set type geography set associated-interface "wan1" set country "SX" next edit "Slovakia - WAN1" set type geography set associated-interface "wan1" set country "SK" next edit "Slovenia - WAN1" set type geography set associated-interface "wan1" set country "SI" next edit "Solomon Islands - WAN1" set type geography set associated-interface "wan1" set country "SB" next edit "Somalia - WAN1" set type geography set associated-interface "wan1" set country "SO" next edit "South Africa - WAN1" set type geography set associated-interface "wan1" set country "ZA" next edit "South Georgia and the South Sandwich Islands - WAN1" set type geography set associated-interface "wan1" set country "GS" next edit "South Sudan - WAN1" set type geography set associated-interface "wan1" set country "SS" next edit "Spain - WAN1" set type geography set associated-interface "wan1" set country "ES" next edit "Sri Lanka - WAN1" set type geography set associated-interface "wan1" set country "LK" next edit "Sudan - WAN1" set type geography set associated-interface "wan1" set country "SD" next edit "Suriname - WAN1" set type geography set associated-interface "wan1" set country "SR" next edit "Svalbard and Jan Mayen - WAN1" set type geography set associated-interface "wan1" set country "SJ" next edit "Swaziland - WAN1" set type geography set associated-interface "wan1" set country "SZ" next edit "Sweden - WAN1" set type geography set associated-interface "wan1" set country "SE" next edit "Switzerland - WAN1" set type geography set associated-interface "wan1" set country "CH" next edit "Syrian Arab Republic - WAN1" set type geography set associated-interface "wan1" set country "SY" next edit "Taiwan - WAN1" set type geography set associated-interface "wan1" set country "TW" next edit "Tajikistan - WAN1" set type geography set associated-interface "wan1" set country "TJ" next edit "Tanzania, United Republic of - WAN1" set type geography set associated-interface "wan1" set country "TZ" next edit "Thailand - WAN1" set type geography set associated-interface "wan1" set country "TH" next edit "Timor-Leste - WAN1" set type geography set associated-interface "wan1" set country "TL" next edit "Togo - WAN1" set type geography set associated-interface "wan1" set country "TG" next edit "Tokelau - WAN1" set type geography set associated-interface "wan1" set country "TK" next edit "Tonga - WAN1" set type geography set associated-interface "wan1" set country "TO" next edit "Trinidad and Tobago - WAN1" set type geography set associated-interface "wan1" set country "TT" next edit "Tunisia - WAN1" set type geography set associated-interface "wan1" set country "TN" next edit "Turkey - WAN1" set type geography set associated-interface "wan1" set country "TR" next edit "Turkmenistan - WAN1" set type geography set associated-interface "wan1" set country "TM" next edit "Turks and Caicos Islands - WAN1" set type geography set associated-interface "wan1" set country "TC" next edit "Tuvalu - WAN1" set type geography set associated-interface "wan1" set country "TV" next edit "Uganda - WAN1" set type geography set associated-interface "wan1" set country "UG" next edit "Ukraine - WAN1" set type geography set associated-interface "wan1" set country "UA" next edit "United Arab Emirates - WAN1" set type geography set associated-interface "wan1" set country "AE" next edit "United Kingdom - WAN1" set type geography set associated-interface "wan1" set country "GB" next edit "United States Minor Outlying Islands - WAN1" set type geography set associated-interface "wan1" set country "UM" next edit "Uruguay - WAN1" set type geography set associated-interface "wan1" set country "UY" next edit "Uzbekistan - WAN1" set type geography set associated-interface "wan1" set country "UZ" next edit "Vanuatu - WAN1" set type geography set associated-interface "wan1" set country "VU" next edit "Venezuela - WAN1" set type geography set associated-interface "wan1" set country "VE" next edit "Vietnam - WAN1" set type geography set associated-interface "wan1" set country "VN" next edit "Virgin Islands, British - WAN1" set type geography set associated-interface "wan1" set country "VG" next edit "Virgin Islands, U.S. - WAN1" set type geography set associated-interface "wan1" set country "VI" next edit "Wallis and Futuna - WAN1" set type geography set associated-interface "wan1" set country "WF" next edit "Western Sahara - WAN1" set type geography set associated-interface "wan1" set country "EH" next edit "Yemen - WAN1" set type geography set associated-interface "wan1" set country "YE" next edit "Zambia - WAN1" set type geography set associated-interface "wan1" set country "ZM" next edit "Zimbabwe - WAN1" set type geography set associated-interface "wan1" set country "ZW" next edit "Afghanistan - WAN2" set type geography set associated-interface "wan2" set country "AF" next edit "Aland Islands - WAN2" set type geography set associated-interface "wan2" set country "AX" next edit "Albania - WAN2" set type geography set associated-interface "wan2" set country "AL" next edit "Algeria - WAN2" set type geography set associated-interface "wan2" set country "DZ" next edit "American Samoa - WAN2" set type geography set associated-interface "wan2" set country "AS" next edit "Andorra - WAN2" set type geography set associated-interface "wan2" set country "AD" next edit "Angola - WAN2" set type geography set associated-interface "wan2" set country "AO" next edit "Anguilla - WAN2" set type geography set associated-interface "wan2" set country "AI" next edit "Antartica - WAN2" set type geography set associated-interface "wan2" set country "AQ" next edit "Antigua and Barbuda - WAN2" set type geography set associated-interface "wan2" set country "AG" next edit "Argentina - WAN2" set type geography set associated-interface "wan2" set country "AR" next edit "Armenia - WAN2" set type geography set associated-interface "wan2" set country "AM" next edit "Aruba - WAN2" set type geography set associated-interface "wan2" set country "AW" next edit "Australia - WAN2" set type geography set associated-interface "wan2" set country "AU" next edit "Austria - WAN2" set type geography set associated-interface "wan2" set country "AT" next edit "Azerbaijan - WAN2" set type geography set associated-interface "wan2" set country "AZ" next edit "Bahamas - WAN2" set type geography set associated-interface "wan2" set country "BS" next edit "Bahrain - WAN2" set type geography set associated-interface "wan2" set country "BH" next edit "Bangladesh - WAN2" set type geography set associated-interface "wan2" set country "BD" next edit "Barbados - WAN2" set type geography set associated-interface "wan2" set country "BB" next edit "Belarus - WAN2" set type geography set associated-interface "wan2" set country "BY" next edit "Belgium - WAN2" set type geography set associated-interface "wan2" set country "BE" next edit "Belize - WAN2" set type geography set associated-interface "wan2" set country "BZ" next edit "Benin - WAN2" set type geography set associated-interface "wan2" set country "BJ" next edit "Bermuda - WAN2" set type geography set associated-interface "wan2" set country "BM" next edit "Bhutan - WAN2" set type geography set associated-interface "wan2" set country "BT" next edit "Bolivia - WAN2" set type geography set associated-interface "wan2" set country "BO" next edit "Bonaire, Saint Eustatius and Saba - WAN2" set type geography set associated-interface "wan2" set country "BQ" next edit "Bosnia and Herzegovina - WAN2" set type geography set associated-interface "wan2" set country "BA" next edit "Botswana - WAN2" set type geography set associated-interface "wan2" set country "BW" next edit "Bouvet Island - WAN2" set type geography set associated-interface "wan2" set country "BV" next edit "Brazil - WAN2" set type geography set associated-interface "wan2" set country "BR" next edit "British Indian Ocean Territory - WAN2" set type geography set associated-interface "wan2" set country "IO" next edit "Brunei Darussalam - WAN2" set type geography set associated-interface "wan2" set country "BN" next edit "Bulgaria - WAN2" set type geography set associated-interface "wan2" set country "BG" next edit "Burkina Faso - WAN2" set type geography set associated-interface "wan2" set country "BF" next edit "Burundi - WAN2" set type geography set associated-interface "wan2" set country "BI" next edit "Cambodia - WAN2" set type geography set associated-interface "wan2" set country "KH" next edit "Cameroon - WAN2" set type geography set associated-interface "wan2" set country "CM" next edit "Canada - WAN2" set type geography set associated-interface "wan2" set country "CA" next edit "Cape Verde - WAN2" set type geography set associated-interface "wan2" set country "CV" next edit "Cayman Islands Central African Republic - WAN2" set type geography set associated-interface "wan2" set country "" next edit "Chad - WAN2" set type geography set associated-interface "wan2" set country "TD" next edit "Chile - WAN2" set type geography set associated-interface "wan2" set country "CL" next edit "China - WAN2" set type geography set associated-interface "wan2" set country "CN" next edit "Christmas Island - WAN2" set type geography set associated-interface "wan2" set country "KY" next edit "Cocos (Keeling) Islands - WAN2" set type geography set associated-interface "wan2" set country "CC" next edit "Colombia - WAN2" set type geography set associated-interface "wan2" set country "CO" next edit "Comoros - WAN2" set type geography set associated-interface "wan2" set country "KM" next edit "Congo - WAN2" set type geography set associated-interface "wan2" set country "CG" next edit "Congo, The Democratic Republic of the - WAN2" set type geography set associated-interface "wan2" set country "CD" next edit "Cook Islands - WAN2" set type geography set associated-interface "wan2" set country "CK" next edit "Costa Rica - WAN2" set type geography set associated-interface "wan2" set country "CR" next edit "Cote d'Ivoire - WAN2" set type geography set associated-interface "wan2" set country "CI" next edit "Croatia - WAN2" set type geography set associated-interface "wan2" set country "HR" next edit "Cuba - WAN2" set type geography set associated-interface "wan2" set country "CU" next edit "Curacao - WAN2" set type geography set associated-interface "wan2" set country "CW" next edit "Cyprus - WAN2" set type geography set associated-interface "wan2" set country "CY" next edit "Czech Republic - WAN2" set type geography set associated-interface "wan2" set country "CZ" next edit "Denmark - WAN2" set type geography set associated-interface "wan2" set country "DK" next edit "Djibouti - WAN2" set type geography set associated-interface "wan2" set country "DJ" next edit "Dominica - WAN2" set type geography set associated-interface "wan2" set country "DM" next edit "Dominican Republic - WAN2" set type geography set associated-interface "wan2" set country "DO" next edit "Ecuador - WAN2" set type geography set associated-interface "wan2" set country "EC" next edit "Egypt - WAN2" set type geography set associated-interface "wan2" set country "EG" next edit "El Salvador - WAN2" set type geography set associated-interface "wan2" set country "SV" next edit "Equatorial Guinea - WAN2" set type geography set associated-interface "wan2" set country "GQ" next edit "Eritrea - WAN2" set type geography set associated-interface "wan2" set country "ER" next edit "Estonia - WAN2" set type geography set associated-interface "wan2" set country "EE" next edit "Ethiopia - WAN2" set type geography set associated-interface "wan2" set country "ET" next edit "Falkland Islands (Malvinas) - WAN2" set type geography set associated-interface "wan2" set country "FK" next edit "Faroe Islands - WAN2" set type geography set associated-interface "wan2" set country "FO" next edit "Fiji - WAN2" set type geography set associated-interface "wan2" set country "FJ" next edit "Finland - WAN2" set type geography set associated-interface "wan2" set country "FI" next edit "France - WAN2" set type geography set associated-interface "wan2" set country "FR" next edit "French Guiana - WAN2" set type geography set associated-interface "wan2" set country "GF" next edit "French Polynesia - WAN2" set type geography set associated-interface "wan2" set country "PF" next edit "French Southern Territories - WAN2" set type geography set associated-interface "wan2" set country "TF" next edit "Gabon - WAN2" set type geography set associated-interface "wan2" set country "GA" next edit "Gambia - WAN2" set type geography set associated-interface "wan2" set country "GM" next edit "Georgia - WAN2" set type geography set associated-interface "wan2" set country "GE" next edit "Germany - WAN2" set type geography set associated-interface "wan2" set country "DE" next edit "Ghana - WAN2" set type geography set associated-interface "wan2" set country "GH" next edit "Gibraltar - WAN2" set type geography set associated-interface "wan2" set country "GI" next edit "Greece - WAN2" set type geography set associated-interface "wan2" set country "GR" next edit "Greenland - WAN2" set type geography set associated-interface "wan2" set country "GL" next edit "Grenada - WAN2" set type geography set associated-interface "wan2" set country "GD" next edit "Guadeloupe - WAN2" set type geography set associated-interface "wan2" set country "GP" next edit "Guam - WAN2" set type geography set associated-interface "wan2" set country "GU" next edit "Guatemala - WAN2" set type geography set associated-interface "wan2" set country "GT" next edit "Guernsey - WAN2" set type geography set associated-interface "wan2" set country "GG" next edit "Guinea - WAN2" set type geography set associated-interface "wan2" set country "GN" next edit "Guinea-Bissau - WAN2" set type geography set associated-interface "wan2" set country "GW" next edit "Guyana - WAN2" set type geography set associated-interface "wan2" set country "GY" next edit "Haiti - WAN2" set type geography set associated-interface "wan2" set country "HT" next edit "Heard Island and Mcdonald Islands - WAN2" set type geography set associated-interface "wan2" set country "HM" next edit "Holy See (Vatican City State) - WAN2" set type geography set associated-interface "wan2" set country "VA" next edit "Honduras - WAN2" set type geography set associated-interface "wan2" set country "HN" next edit "Hong Kong - WAN2" set type geography set associated-interface "wan2" set country "HK" next edit "Hungary - WAN2" set type geography set associated-interface "wan2" set country "HU" next edit "Iceland - WAN2" set type geography set associated-interface "wan2" set country "IS" next edit "India - WAN2" set type geography set associated-interface "wan2" set country "IN" next edit "Indonesia - WAN2" set type geography set associated-interface "wan2" set country "ID" next edit "Iran, Islamic Republic of - WAN2" set type geography set associated-interface "wan2" set country "IR" next edit "Iraq - WAN2" set type geography set associated-interface "wan2" set country "IQ" next edit "Ireland - WAN2" set type geography set associated-interface "wan2" set country "IE" next edit "Isle of Man - WAN2" set type geography set associated-interface "wan2" set country "IM" next edit "Israel - WAN2" set type geography set associated-interface "wan2" set country "IL" next edit "Italy - WAN2" set type geography set associated-interface "wan2" set country "IT" next edit "Jamaica - WAN2" set type geography set associated-interface "wan2" set country "JM" next edit "Japan - WAN2" set type geography set associated-interface "wan2" set country "JP" next edit "Jersey - WAN2" set type geography set associated-interface "wan2" set country "JE" next edit "Jordan - WAN2" set type geography set associated-interface "wan2" set country "JO" next edit "Kazakhstan - WAN2" set type geography set associated-interface "wan2" set country "KZ" next edit "Kenya - WAN2" set type geography set associated-interface "wan2" set country "KE" next edit "Kiribati - WAN2" set type geography set associated-interface "wan2" set country "KI" next edit "North Korea - WAN2" set type geography set associated-interface "wan2" set country "KP" next edit "South Korea - WAN2" set type geography set associated-interface "wan2" set country "KR" next edit "Kosovo - WAN2" set type geography set associated-interface "wan2" set country "XK" next edit "Kuwait - WAN2" set type geography set associated-interface "wan2" set country "KW" next edit "Kyrgyzstan - WAN2" set type geography set associated-interface "wan2" set country "KG" next edit "Lao People's Democratic Republic - WAN2" set type geography set associated-interface "wan2" set country "LA" next edit "Latvia - WAN2" set type geography set associated-interface "wan2" set country "LV" next edit "Lebanon - WAN2" set type geography set associated-interface "wan2" set country "LB" next edit "Lesotho - WAN2" set type geography set associated-interface "wan2" set country "LS" next edit "Liberia - WAN2" set type geography set associated-interface "wan2" set country "LR" next edit "Libya - WAN2" set type geography set associated-interface "wan2" set country "LY" next edit "Liechtenstein - WAN2" set type geography set associated-interface "wan2" set country "LI" next edit "Lithuania - WAN2" set type geography set associated-interface "wan2" set country "LT" next edit "Luxembourg - WAN2" set type geography set associated-interface "wan2" set country "LU" next edit "Macao - WAN2" set type geography set associated-interface "wan2" set country "MO" next edit "Macedonia - WAN2" set type geography set associated-interface "wan2" set country "MK" next edit "Madagascar - WAN2" set type geography set associated-interface "wan2" set country "MG" next edit "Malawi - WAN2" set type geography set associated-interface "wan2" set country "MW" next edit "Malaysia - WAN2" set type geography set associated-interface "wan2" set country "MY" next edit "Maldives - WAN2" set type geography set associated-interface "wan2" set country "MV" next edit "Mali - WAN2" set type geography set associated-interface "wan2" set country "ML" next edit "Malta - WAN2" set type geography set associated-interface "wan2" set country "MT" next edit "Marshall Islands - WAN2" set type geography set associated-interface "wan2" set country "MH" next edit "Martinique - WAN2" set type geography set associated-interface "wan2" set country "MQ" next edit "Mauritania - WAN2" set type geography set associated-interface "wan2" set country "MR" next edit "Mauritius - WAN2" set type geography set associated-interface "wan2" set country "MU" next edit "Mayotte - WAN2" set type geography set associated-interface "wan2" set country "YT" next edit "Mexico - WAN2" set type geography set associated-interface "wan2" set country "MX" next edit "Micronesia, Federated States of - WAN2" set type geography set associated-interface "wan2" set country "FM" next edit "Moldova, Republic of - WAN2" set type geography set associated-interface "wan2" set country "MD" next edit "Monaco - WAN2" set type geography set associated-interface "wan2" set country "MC" next edit "Mongolia - WAN2" set type geography set associated-interface "wan2" set country "MN" next edit "Montenegro - WAN2" set type geography set associated-interface "wan2" set country "ME" next edit "Montserrat - WAN2" set type geography set associated-interface "wan2" set country "MS" next edit "Morocco - WAN2" set type geography set associated-interface "wan2" set country "MA" next edit "Mozambique - WAN2" set type geography set associated-interface "wan2" set country "MZ" next edit "Myanmar - WAN2" set type geography set associated-interface "wan2" set country "MM" next edit "Namibia - WAN2" set type geography set associated-interface "wan2" set country "NA" next edit "Nauru - WAN2" set type geography set associated-interface "wan2" set country "NR" next edit "Nepal - WAN2" set type geography set associated-interface "wan2" set country "NP" next edit "Netherlands - WAN2" set type geography set associated-interface "wan2" set country "NL" next edit "Netherlands Antilles - WAN2" set type geography set associated-interface "wan2" set country "AN" next edit "New Caledonia - WAN2" set type geography set associated-interface "wan2" set country "NC" next edit "New Zealand - WAN2" set type geography set associated-interface "wan2" set country "NZ" next edit "Nicaragua - WAN2" set type geography set associated-interface "wan2" set country "NI" next edit "Niger - WAN2" set type geography set associated-interface "wan2" set country "NE" next edit "Nigeria - WAN2" set type geography set associated-interface "wan2" set country "NG" next edit "Niue - WAN2" set type geography set associated-interface "wan2" set country "NU" next edit "Norfolk Island - WAN2" set type geography set associated-interface "wan2" set country "NF" next edit "Northern Mariana Islands - WAN2" set type geography set associated-interface "wan2" set country "MP" next edit "Norway - WAN2" set type geography set associated-interface "wan2" set country "NO" next edit "Oman - WAN2" set type geography set associated-interface "wan2" set country "OM" next edit "Pakistan - WAN2" set type geography set associated-interface "wan2" set country "PK" next edit "Palau - WAN2" set type geography set associated-interface "wan2" set country "PW" next edit "Palestinian Territory - WAN2" set type geography set associated-interface "wan2" set country "PS" next edit "Panama - WAN2" set type geography set associated-interface "wan2" set country "PA" next edit "Papua New Guinea - WAN2" set type geography set associated-interface "wan2" set country "PG" next edit "Paraguay - WAN2" set type geography set associated-interface "wan2" set country "PY" next edit "Peru - WAN2" set type geography set associated-interface "wan2" set country "PE" next edit "Philippines - WAN2" set type geography set associated-interface "wan2" set country "PH" next edit "Pitcairn - WAN2" set type geography set associated-interface "wan2" set country "PN" next edit "Poland - WAN2" set type geography set associated-interface "wan2" set country "PL" next edit "Portugal - WAN2" set type geography set associated-interface "wan2" set country "PT" next edit "Puerto Rico - WAN2" set type geography set associated-interface "wan2" set country "PR" next edit "Qatar - WAN2" set type geography set associated-interface "wan2" set country "QA" next edit "Romania - WAN2" set type geography set associated-interface "wan2" set country "RO" next edit "Russian Federation - WAN2" set type geography set associated-interface "wan2" set country "RU" next edit "Rwanda - WAN2" set type geography set associated-interface "wan2" set country "RW" next edit "Saint Bartelemey - WAN2" set type geography set associated-interface "wan2" set country "BL" next edit "Saint Helena - WAN2" set type geography set associated-interface "wan2" set country "SH" next edit "Saint Kitts and Nevis - WAN2" set type geography set associated-interface "wan2" set country "KN" next edit "Saint Lucia - WAN2" set type geography set associated-interface "wan2" set country "LC" next edit "Saint Martin - WAN2" set type geography set associated-interface "wan2" set country "MF" next edit "Saint Pierre and Miquelon - WAN2" set type geography set associated-interface "wan2" set country "PM" next edit "Saint Vincent and the Grenadines - WAN2" set type geography set associated-interface "wan2" set country "VC" next edit "Samoa - WAN2" set type geography set associated-interface "wan2" set country "WS" next edit "San Marino - WAN2" set type geography set associated-interface "wan2" set country "SM" next edit "Sao Tome and Principe - WAN2" set type geography set associated-interface "wan2" set country "ST" next edit "Saudi Arabia - WAN2" set type geography set associated-interface "wan2" set country "SA" next edit "Senegal - WAN2" set type geography set associated-interface "wan2" set country "SN" next edit "Serbia - WAN2" set type geography set associated-interface "wan2" set country "RS" next edit "Seychelles - WAN2" set type geography set associated-interface "wan2" set country "SC" next edit "Sierra Leone - WAN2" set type geography set associated-interface "wan2" set country "SL" next edit "Singapore - WAN2" set type geography set associated-interface "wan2" set country "SG" next edit "Sint Maarten - WAN2" set type geography set associated-interface "wan2" set country "SX" next edit "Slovakia - WAN2" set type geography set associated-interface "wan2" set country "SK" next edit "Slovenia - WAN2" set type geography set associated-interface "wan2" set country "SI" next edit "Solomon Islands - WAN2" set type geography set associated-interface "wan2" set country "SB" next edit "Somalia - WAN2" set type geography set associated-interface "wan2" set country "SO" next edit "South Africa - WAN2" set type geography set associated-interface "wan2" set country "ZA" next edit "South Georgia and the South Sandwich Islands - WAN2" set type geography set associated-interface "wan2" set country "GS" next edit "South Sudan - WAN2" set type geography set associated-interface "wan2" set country "SS" next edit "Spain - WAN2" set type geography set associated-interface "wan2" set country "ES" next edit "Sri Lanka - WAN2" set type geography set associated-interface "wan2" set country "LK" next edit "Sudan - WAN2" set type geography set associated-interface "wan2" set country "SD" next edit "Suriname - WAN2" set type geography set associated-interface "wan2" set country "SR" next edit "Svalbard and Jan Mayen - WAN2" set type geography set associated-interface "wan2" set country "SJ" next edit "Swaziland - WAN2" set type geography set associated-interface "wan2" set country "SZ" next edit "Sweden - WAN2" set type geography set associated-interface "wan2" set country "SE" next edit "Switzerland - WAN2" set type geography set associated-interface "wan2" set country "CH" next edit "Syrian Arab Republic - WAN2" set type geography set associated-interface "wan2" set country "SY" next edit "Taiwan - WAN2" set type geography set associated-interface "wan2" set country "TW" next edit "Tajikistan - WAN2" set type geography set associated-interface "wan2" set country "TJ" next edit "Tanzania, United Republic of - WAN2" set type geography set associated-interface "wan2" set country "TZ" next edit "Thailand - WAN2" set type geography set associated-interface "wan2" set country "TH" next edit "Timor-Leste - WAN2" set type geography set associated-interface "wan2" set country "TL" next edit "Togo - WAN2" set type geography set associated-interface "wan2" set country "TG" next edit "Tokelau - WAN2" set type geography set associated-interface "wan2" set country "TK" next edit "Tonga - WAN2" set type geography set associated-interface "wan2" set country "TO" next edit "Trinidad and Tobago - WAN2" set type geography set associated-interface "wan2" set country "TT" next edit "Tunisia - WAN2" set type geography set associated-interface "wan2" set country "TN" next edit "Turkey - WAN2" set type geography set associated-interface "wan2" set country "TR" next edit "Turkmenistan - WAN2" set type geography set associated-interface "wan2" set country "TM" next edit "Turks and Caicos Islands - WAN2" set type geography set associated-interface "wan2" set country "TC" next edit "Tuvalu - WAN2" set type geography set associated-interface "wan2" set country "TV" next edit "Uganda - WAN2" set type geography set associated-interface "wan2" set country "UG" next edit "Ukraine - WAN2" set type geography set associated-interface "wan2" set country "UA" next edit "United Arab Emirates - WAN2" set type geography set associated-interface "wan2" set country "AE" next edit "United Kingdom - WAN2" set type geography set associated-interface "wan2" set country "GB" next edit "United States Minor Outlying Islands - WAN2" set type geography set associated-interface "wan2" set country "UM" next edit "Uruguay - WAN2" set type geography set associated-interface "wan2" set country "UY" next edit "Uzbekistan - WAN2" set type geography set associated-interface "wan2" set country "UZ" next edit "Vanuatu - WAN2" set type geography set associated-interface "wan2" set country "VU" next edit "Venezuela - WAN2" set type geography set associated-interface "wan2" set country "VE" next edit "Vietnam - WAN2" set type geography set associated-interface "wan2" set country "VN" next edit "Virgin Islands, British - WAN2" set type geography set associated-interface "wan2" set country "VG" next edit "Virgin Islands, U.S. - WAN2" set type geography set associated-interface "wan2" set country "VI" next edit "Wallis and Futuna - WAN2" set type geography set associated-interface "wan2" set country "WF" next edit "Western Sahara - WAN2" set type geography set associated-interface "wan2" set country "EH" next edit "Yemen - WAN2" set type geography set associated-interface "wan2" set country "YE" next edit "Zambia - WAN2" set type geography set associated-interface "wan2" set country "ZM" next edit "Zimbabwe - WAN2" set type geography set associated-interface "wan2" set country "ZW" next end

5 REPLIES 5
dsykora
New Contributor II

We had a similar need (only allow outgoing connections to US geography only).  For each vlan X to sdwan rule, we replaced destination ALL with an address we created called USAips that has type=Geography and Country/Region=US.  We also created a NonUSAips address group and added exceptions to it.

 

So basically instead denying hundreds of countries, we just allowed the one country.

emnoc
Esteemed Contributor III

Same, we have an address-group with  12-14 counties in Americas/Asia/Europe that we allow and use that in place of "all"

 

Much simpler imo vrs blocking  280 plus countries

 

ken felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Yurisk

Thanks for the sharing, as others have said using Allow to US and Block everything else could be easier:

1) Rule using Geo address of US as destination with action: allow, then explicit/implicit block All

2) Rule with US Geo address in destination with NEGATE on and action Block, and below this destination All, action:allow

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
knowles13088
New Contributor

Thanks, @stsbrad! 

ede_pfau

I've posted ready-to-use address groups on my site a couple of years ago (here). I'm not so much a fan of associating objects to an interface (there are FGTs which do not a "wan1"). There is no easy way to get rid of it when necessary.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors