Skip to main content
DHNX
Explorer
July 24, 2025
Question

Snort IP Blocklist Feed Not Returning IPs in FortiSOAR

  • July 24, 2025
  • 0 replies
  • 423 views

Hi everyone,

I’m using the Snort IP Blocklist Feed connector in FortiSOAR to pull threat indicators. The setup and health check look good, but when I run the Get Indicators action, I only get the Terms and Conditions HTML page instead of the actual IP list.

I noticed that after accepting the terms manually in a browser, a signed URL is generated which points to the real blocklist file. This signed link seems temporary and can’t be used directly in the connector.

Can anyone help with:
Is there a way to automate the terms acceptance or get the IP list via an API?

Has anyone figured out how to work around this in FortiSOAR?

Any help or suggestions would be appreciated!