Skip to main content

3 replies

gschmitt
New Member
December 15, 2015

You mean all traffic?

Go to Policy & Objects > Objects > Addresses and click Create New

Name: badIP (or whatever)

Type IP/Netmask

Subnet / IP Range 63.247.65.42

Hit OK

 

OPTIONAL:

If you plan to repeat the process with other IPs click the down arrow next to Create New :downwards_button: and select Address Group

Name: badIPs (or whatever) and add the IPs to the members menu.

OK

 

Go to Policy & Objects > Policy > IPv4 and Create New

Incoming Interface: internal (or where your clients are located)

Source Address: all (unless you have an object for your internal network)

Outgoing Interface: wan (your internet facing interface)

Destiation Address: badIP(s)

Service: any

Action: Deny

OK

 

Test and done.

madunix
madunixAuthor
New Member
December 15, 2015

Is it safe to block this IP...

madunix
madunixAuthor
New Member
December 15, 2015

checked in virustotal

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.