Fortinet white logo
Fortinet white logo

Admin Guide

26.1.a

Creating an impossible-to-travel policy

Creating an impossible-to-travel policy

The Impossible Travel feature helps to improve the security level and blocks suspicious login attempts when FortiIdentity Cloud detects an unusual login request far away from a reasonable geographical location. For example, if after a user logs in from New york and there is another login attempt from San Francisco by the same user in a period of time that is impossible to travel from New York to San Francisco, it can be blocked. FIC is able to identify suspicious sign-in attempts based on distance and time elapsed between two subsequent user sign-in attempts. Bear in mind that the user IP must be supported by FortiProducts.

To enable the Impossible Travel feature in an adaptive authentication policy:
  1. Click Adaptive Auth > Policies.
  2. Select Add Policy.
  3. Specify the policy name.
  4. For Action, select Block.
  5. For Filters, select Location Filter.
  6. Select the Impossible Travel button to enable it.
  7. For Schedule, select a desired schedule set.
  8. Click Apply.
  9. Add the new policy into a profile, and be sure to select the Default action as Multi-factor Authentication. This will ensure that when the impossible travel policy is not met, the user will be prompted for multi-factor authentication and can proceed to log in. If the impossible travel condition is met, the user will be blocked based on the policy.

  10. Add the new profile into any application (including FortiProducts and web apps) and any realm whose users are going to log in from the specified locations.

Creating an impossible-to-travel policy

Creating an impossible-to-travel policy

The Impossible Travel feature helps to improve the security level and blocks suspicious login attempts when FortiIdentity Cloud detects an unusual login request far away from a reasonable geographical location. For example, if after a user logs in from New york and there is another login attempt from San Francisco by the same user in a period of time that is impossible to travel from New York to San Francisco, it can be blocked. FIC is able to identify suspicious sign-in attempts based on distance and time elapsed between two subsequent user sign-in attempts. Bear in mind that the user IP must be supported by FortiProducts.

To enable the Impossible Travel feature in an adaptive authentication policy:
  1. Click Adaptive Auth > Policies.
  2. Select Add Policy.
  3. Specify the policy name.
  4. For Action, select Block.
  5. For Filters, select Location Filter.
  6. Select the Impossible Travel button to enable it.
  7. For Schedule, select a desired schedule set.
  8. Click Apply.
  9. Add the new policy into a profile, and be sure to select the Default action as Multi-factor Authentication. This will ensure that when the impossible travel policy is not met, the user will be prompted for multi-factor authentication and can proceed to log in. If the impossible travel condition is met, the user will be blocked based on the policy.

  10. Add the new profile into any application (including FortiProducts and web apps) and any realm whose users are going to log in from the specified locations.