Skip to main content
sbabu
Staff
Staff
December 31, 2024

Technical Tip: How to configure STIX2.0 external threat feed server in FortiGate

  • December 31, 2024
  • 0 replies
  • 927 views
Description

 

This article explains how to configure the STIX2.0 external threat feed server in FortiGate.

 

Scope

 

FortiGate, an External Threat feed server.

 

Solution

 

Log on to any external threat feed server with user credentials. 

 

Step 1:

  • To obtain the actual link, which must be configured on the FortiGate, take out the red-marked token value from the preceding URL: stix://otx.alienvault.com/otxapi/pulses/668cc34398c8a69a93af9ec2/export/?&format=stix2.0

Step 2:

  • Configure an external Threat feed server in FortiGate by navigating to Security Fabric -> external connectors -> Scroll down to locate threat feeds and select the FortiGuard category.
  • In connector settings, configure the threat feed server with STIX link and user key as username as shown below.

 

Alien-3 (1).png

 

  • Once configured, the FortiGate will pool feeds from the server.

 

alien-2 (3).png

 

The logs below can be collected to identify the issue further if it gives the same error.

 

exec ping <external threat feed server IP>

Putty2:

 

dia sniffer packet any "host x.x.x.x" 6 0 a

Putty3:


dia de reset
dia de app forticron 0xf00
dia de console timestamp enable
dia de enable