Fortinet white logo
Fortinet white logo

CLI Reference

profile geoip-group

profile geoip-group

Use this command to create groups of IP addresses using the GeoIP database from FortiGuard.

FortiMail can use the GeoIP database to map geographic locations to IP addresses. You can use GeoIP groups for geo-targeting of countries that require different policies, or regions that are only sources of misuse, spam, and viruses. The GeoIP database saves time instead of manually defining and updating a list of global public IP addresses.

To apply a GeoIP group, select it in an IP-based policy or access control rule.

Note

For better performance, use GeoIP groups in IP-based policies instead of access control rules. This blocks unwanted connections earlier, before authentication.

(Access control rules block unwanted connections after authentication. This wastes time and system resources. If there are back-end servers for authentication, recipient verification, etc., then the unwanted connections also will continue to effect those servers.)

Syntax

config profile geoip-group

edit name <group_name>

[set description "<comment_str>"]

set country {ZZ O1 AD ...}

end

Variable

Description

Default

name <group_name>

Enter a unique name.

description "<comment_str>" Enter a comment or description.

country {ZZ O1 AD ...}

Enter a country code. Separate multiple geographic regions with a space.

To display a list of currently known country codes, enter:

set country ?

Related topics

system geoip-override

policy access-control delivery

policy access-control receive

policy ip

profile geoip-group

profile geoip-group

Use this command to create groups of IP addresses using the GeoIP database from FortiGuard.

FortiMail can use the GeoIP database to map geographic locations to IP addresses. You can use GeoIP groups for geo-targeting of countries that require different policies, or regions that are only sources of misuse, spam, and viruses. The GeoIP database saves time instead of manually defining and updating a list of global public IP addresses.

To apply a GeoIP group, select it in an IP-based policy or access control rule.

Note

For better performance, use GeoIP groups in IP-based policies instead of access control rules. This blocks unwanted connections earlier, before authentication.

(Access control rules block unwanted connections after authentication. This wastes time and system resources. If there are back-end servers for authentication, recipient verification, etc., then the unwanted connections also will continue to effect those servers.)

Syntax

config profile geoip-group

edit name <group_name>

[set description "<comment_str>"]

set country {ZZ O1 AD ...}

end

Variable

Description

Default

name <group_name>

Enter a unique name.

description "<comment_str>" Enter a comment or description.

country {ZZ O1 AD ...}

Enter a country code. Separate multiple geographic regions with a space.

To display a list of currently known country codes, enter:

set country ?

Related topics

system geoip-override

policy access-control delivery

policy access-control receive

policy ip