Block specific outgoing IP address on a FortGate 100E Firewall

Hi,

I have need to block specific external IP addresses from being reached. The firewall is a FortiGate 100E appliance.
This can be done because I was shown once recently but have since forgotten how .  
I essentially want to stop all outgoing traffic to reach the IPs - completely block. No DNS names, all IP.

The reason is to block known mailicious IPs and discovered IPs that viruses attempt to send data to while I address the issues as a delayed response tech - at least I can remote in and block the IPs from being reached until I get onsite or perform remote sessions.

Please advise how to do so via the GUI, not just CLI. Or, both ways but definitely via GUI. Editing Host files is not an option.

Thanks in advance for your assistance.
LVL 14
Michael MachieIT SupervisorAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Garry GlendownConsulting and Network/Security SpecialistCommented:
Go to the firewall policies, and for the interface pairing of the inside to the outside interface, insert a new policy at the beginning with "deny" for the specific destination IP. You will have to create the appropriate IP object, which you can do inside the interface.
Depending on the OS version it could look something like this:
Policy definition
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Michael MachieIT SupervisorAuthor Commented:
Thanks Garry. I will get onto that system and try this out.

Need to inform you that Im not able to do this work remotely just yet - this new device is being installed over the weekend, so I'll send an update as soon as I have one but it will be at least after the weekend.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.