An administrator must restrict endpoints from certain countries from connecting to FortiSASE. Which configuration can achieve this? (Choose one answer)
A.
A network lockdown policy on the endpoint profiles
B.
Source IP anchoring to restrict access from the specified countries
C.
A geography address object as the source for a deny policy
D.
Geofencing to restrict access from the required countries
To restrict endpoints from certain countries from connecting to FortiSASE, the administrator should configure Geofencing. This feature provides granular control over which geographic locations are permitted or denied access to the SASE infrastructure.
Geofencing in FortiSASE
Geofencing is the primary mechanism for controlling remote user connectivity based on their origin.
Functionality: It uses a geography-to-IP mapping database to identify the location of incoming connection requests.
Access Modes: Administrators can choose between two main modes:
Allow: Only users from specified countries can connect; all others are blocked.
Deny: Users from specified countries are blocked; all others are allowed.
Configuration Path: In the FortiSASE GUI, navigate to Configuration > Geofencing to enable the feature and add the relevant countries.
Enforcement: Once enabled, the system automatically creates "local-in" policies to drop or permit traffic at the edge of the SASE PoPs before it can consume resources or attempt authentication.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit