Managing access based on geographic location is one of the most effective ways to secure your network. With FortiGate firewalls, you can create country address objects and use them in your security policies to block or allow traffic from specific countries.
This FortiGate Country Address Object Generator helps you do exactly that — automatically generating the required CLI commands for creating geolocation-based address objects on your FortiGate device.
FortiGate Country Address Object Generator
Select countries to generate FortiGate CLI commands:
Why to Use this Generator?
Instead of manually typing commands for each country, simply select the countries from the list below, and the generator will produce ready-to-use CLI code such as:
config firewall address
edit "Brazil"
set type geography
set country "BR"
next
edit "Italy"
set type geography
set country "IT"
next
end
You can then copy the generated code and paste it directly into your FortiGate CLI or a configuration script.
This tool is especially useful when setting up firewall policies that restrict access to open ports for certain countries, or when you want to allow connections only from trusted regions.
It works entirely in your browser — no data is sent or stored on any server. This makes it fast, private, and secure.
Use the generator below and simplify your FortiGate configuration today!
Conclusion
This free web-based generator helps FortiGate administrators automate the creation of geolocation-based firewall address objects quickly and efficiently. No installation, no login, and no data collection — all actions happen locally in your browser.
ADVERTISEMENT
Use the tool below to generate, copy, or download your FortiGate CLI configuration and improve your network security with country-based access control.
Related FortiGate Tutorials
If you want to learn more about how to use these address objects in your firewall policies, check out these related guides: