Skip to main content
carabhavi
Staff
Staff
May 2, 2020

Technical Tip: IP reputation filtering

  • May 2, 2020
  • 0 replies
  • 5835 views

Description

 

This article describes the 'IP Reputation Filtering' levels and steps to enable the feature.
This feature adds support for reputation filtering in the firewall policies.

 

Scope

 

FortiOS 6.4 (available in 7.0 and newer versions only via CLI, and only for backward compatibility).

Solution


There are five reputation levels in the internet-service database (ISDB), and custom reputation levels can be defined in a custom internet-service. This feature allows firewall policies to filter traffic according to the configured reputation level.

If the reputation level of either the source or destination IP address is equal to or greater than the level set in the policy, then the packet is forwarded, otherwise, the packet is dropped.


The five default reputation levels are:

  1. Known malicious sites related to botnet servers, phishing sites, etc.
  2. Sites providing high-risk services, such as TOR, proxy, P2P, etc.
  3. Unverified sites.
  4. Reputable sites from social media, such as Facebook, Twitter, etc.
  5. Known and verified safe sites, such as Gmail, Amazon, eBay, etc.

To set the reputation level and direction of a policy.

 

config firewall policy
    edit 1
        set uuid dfcaec9c-e925-51e8-cf3e-fed9a1d42a1c
        set srcintf "port1"
        set dstintf "wan1"
        set dstaddr "all"
        set reputation-minimum 3
        set reputation-direction source
        set action accept
        set schedule "always"
        set service "ALL"
        set logtraffic all
        set auto-asic-offload disable
        set nat enable
    next
end

 

Packets from the source IP address with reputation levels three, four, or five will be forwarded by this policy.  If an IP is missing in the ISDB, that IP will get a reputation of Level 3 since it's considered as part of 'Unverified sites'. Therefore, the IP will pass the check in this case, and traffic will be allowed. 

 
In a policy, if 'reputation-minimum' is set, and the reputation-direction is the destination, then the 'dstaddr', service, and 'internet-service' options are removed from the policy.
If reputation-minimum is set, and the reputation-direction is source, then the 'srcaddr', and 'internet-service-src' options are removed from the policy.
 
Related articles:
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!