BAN IP LIST
So I am seeing lots of scanning and trials to connect from different countries across the globe.
All has been denied by the explicit deny policy "0" on the Fortigate. however, after few searches I was recommended to create External IP threat feed and add it a deny rule to ban these IPs.
So, I am seeing the same behavior but instead of being blocked by Policy"0" it is being blocked by the new deny policy. so I don't understand what the point is of doing that instead of letting the explicit deny policy "0" handle it.
Your feedback is appreciated.

