Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Seppel
Contributor II

Geoblocking to one URL

Hi We have several websites on a web server with one IP address. is it possible to use geobloking with fortigate to one website on the server? the other websites should not be affected.

 

Regards.

 

Andy

Fortigate 500E HA Fortimail 200 Fortimanager

FortiEMS

FortiSandbox 1000D

FortiSwitch Network Some other Models in use :-) ---------------------------------------------------- FCSE ----------------------------------------------------

Fortigate 500E HA Fortimail 200 Fortimanager FortiEMS FortiSandbox 1000D FortiSwitch Network Some other Models in use :-) ---------------------------------------------------- FCSE ----------------------------------------------------
4 REPLIES 4
Paul_W_Crane_FTNT

Sorry about that, I misunderstood the question.  Dave is correct, you'll have to give that website a unique IP to use Geoblock for inbound connections.

ede_pfau
Esteemed Contributor III

No, I don't think the WF is the right tool for what you are planning to do.

 

Geoblocking only looks at the source IP range, mapped to a country.

Webfilter only looks at the URL, and cannot be chained to another filter if the action is BLOCK. In general, WF would need to be used as a matching criterium in a policy, but a FGT can only match on addresses, ports, schedule and user.

 

Wait, a policy could match on an FQDN destination address. If you combine that with an country specific source address group you could create a policy which matches both to block that traffic. You could give that a try.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Dave_Hall
Honored Contributor

Could be wrong in this assumption, but it kinda looks like Andy is asking to block specified country hosts from accessing a hosted web site on a web server that is behind the fgt. 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Seppel

thanks for your contributions. it is as dave suspects, the webserver is in the dmz, the webserver has several websites on one IP address and i would like to allow outside access to this page only from selected countries. I have already done some tests, but none of them have brought the solution. I will probably have to add another ip address on the server

 

Greets

Andy

Fortigate 500E HA Fortimail 200 Fortimanager

FortiEMS

FortiSandbox 1000D

FortiSwitch Network Some other Models in use :-) ---------------------------------------------------- FCSE ----------------------------------------------------

Fortigate 500E HA Fortimail 200 Fortimanager FortiEMS FortiSandbox 1000D FortiSwitch Network Some other Models in use :-) ---------------------------------------------------- FCSE ----------------------------------------------------
Labels
Top Kudoed Authors