Skip to main content
ro_phil
New Member
September 17, 2021
Question

Blocking ICMP from malicious IP

  • September 17, 2021
  • 2 replies
  • 2839 views

Hi All,

 

I have a question related to blocking ICMP from a malicious IP on the FortiGate.

 

We have allowed ICMP to one of our sever from external. We see that ICMP was allowed from a malicious IP though it was categorized by FGD as malware. We have all the security profiles enabled for the VIP policy in FGT.

 

Is there a way to block ICMP from malicious IP's?

 

Thanks!

2 replies

ESCHAN_FTNT
Staff
Staff
November 19, 2021

Hi ro_phil

 

If you have the malicious IP, just create a firewall policy with the malicious IP as source address and action set to deny.

brudy
New Member
November 20, 2021

You can create a reputation policy:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-IP-reputation-in-policies-and-fallthrough/ta-p/193898?externalID=FD46815

 

Or you can create a deny policy using these Internet Service Database Objects as source. 

- Botnet-C&C.Server

- Malicious-Malicious

- Malicious-Malicious.Server

- Phishing-Phishing.Server

- Spam-Soamming.Server

- Tor-Exit.Node

 

In this case, do not forget to "set match-vip enable" on this policy. Has to be done on the CLI.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!