An administrator must restrict endpoints from certain countries from connecting to FortiSASE. Which configuration can achieve this? (Choose one answer)
AnswerD
ExplanationTo restrict endpoints from certain countries from connecting to FortiSASE, the administrator should configure Geofencing. This feature provides granular control over which geographic locations are permitted or denied access to the SASE infrastructure.
Geofencing in FortiSASE
Geofencing is the primary mechanism for controlling remote user connectivity based on their origin.
Functionality: It uses a geography-to-IP mapping database to identify the location of incoming connection requests.
Access Modes: Administrators can choose between two main modes:
Allow: Only users from specified countries can connect; all others are blocked.
Deny: Users from specified countries are blocked; all others are allowed.
Configuration Path: In the FortiSASE GUI, navigate to Configuration > Geofencing to enable the feature and add the relevant countries.
Enforcement: Once enabled, the system automatically creates 'local-in' policies to drop or permit traffic at the edge of the SASE PoPs before it can consume resources or attempt authentication.