Hot!Since FortiOS7 address type geography is not possible anymore

Author
ipranger
Gold Member
  • Total Posts : 152
  • Scores: 2
  • Reward points: 0
  • Joined: 2012/11/13 11:49:10
  • Location: Austria/Steiermark
  • Status: offline
2021/05/13 12:18:53 (permalink)
0

Since FortiOS7 address type geography is not possible anymore

Hello all, 
 
i i would like to add an countryblocker with type geography, the system did no allow that. The errormessage at the CMD is very strange.
Can not be geography address when it is a member of addrgrp used by ipsec_tunnel!

But this is a new object, so no member of anything. Is there anything that can be done? Is this a bug?
 
Very thanks and best Regards

Fortigate 60E v7.x (GA)
#1

5 Replies Related Threads

    lobstercreed
    Expert Member
    • Total Posts : 416
    • Scores: 51
    • Reward points: 0
    • Joined: 2018/11/28 14:57:58
    • Location: Sedalia, MO
    • Status: offline
    Re: Since FortiOS7 address type geography is not possible anymore 2021/05/14 04:31:43 (permalink)
    0
    Interesting.  I have not jumped to 7.0 even at my home because of previous experiences with .0 releases.  I would guess this is a bug, and it'd help the rest of us out if you could open a support ticket for it.  :-)
    #2
    ipranger
    Gold Member
    • Total Posts : 152
    • Scores: 2
    • Reward points: 0
    • Joined: 2012/11/13 11:49:10
    • Location: Austria/Steiermark
    • Status: offline
    Re: Since FortiOS7 address type geography is not possible anymore 2021/05/14 06:18:15 (permalink)
    0
    lobstercreed
    Interesting.  I have not jumped to 7.0 even at my home because of previous experiences with .0 releases.  I would guess this is a bug, and it'd help the rest of us out if you could open a support ticket for it.  :-)

    Created :-) Now waiting...

    Fortigate 60E v7.x (GA)
    #3
    emnoc
    Expert Member
    • Total Posts : 6137
    • Scores: 422
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: Since FortiOS7 address type geography is not possible anymore 2021/05/14 11:58:29 (permalink)
    0
    I do not have any issue creating geo block
     
     
    SOCPUPFGT02 (address) # edit USAnew entry 'USA' added SOCPUPFGT02 (USA) # set type geography  SOCPUPFGT02 (USA) # set country US SOCPUPFGT02 (USA) # end fortios7.0  I also tried in WebGUI alsoKen Felix
    post edited by emnoc - 2021/05/18 18:30:44

    PCNSE 
    NSE 
    StrongSwan  
    #4
    ipranger
    Gold Member
    • Total Posts : 152
    • Scores: 2
    • Reward points: 0
    • Joined: 2012/11/13 11:49:10
    • Location: Austria/Steiermark
    • Status: offline
    Re: Since FortiOS7 address type geography is not possible anymore 2021/05/14 15:03:14 (permalink)
    0
    Strange, maybe only in policy based mode? In any case, Fortinet probably sees things differently, and the whole thing goes to a senior engineer. It will be interesting.

    Fortigate 60E v7.x (GA)
    #5
    ipranger
    Gold Member
    • Total Posts : 152
    • Scores: 2
    • Reward points: 0
    • Joined: 2012/11/13 11:49:10
    • Location: Austria/Steiermark
    • Status: offline
    Re: Since FortiOS7 address type geography is not possible anymore 2021/05/18 10:05:05 (permalink)
    0
    Support checked the whole thing and found out that for some reason only one S2S VPN blocks this.
    It is sufficient to set the source and destination to all/all in VPN phase 2, and it is already possible to create geo addresses.
    The Support was even able to verify this in the lab. Unfortunately, it is not clear why this happens.

    Fortigate 60E v7.x (GA)
    #6
    Jump to:
    © 2021 APG vNext Commercial Version 5.5