Skip to main content
JP57
Visitor III
December 31, 2025
Question

FGT address object from FAC logs?

  • December 31, 2025
  • 2 replies
  • 223 views

Is it possible to create an address object on a FGT using logs from a FAC via an event handler on a FAZ?

 

We  setup several automation stitches on the FAZ and FGT to add address objects based on failed VPN attempts.  What I'm also looking to do, if possible, is create an object from a failed login attempt. 

 

Basically, there are hosts out there throwing names and passwords at us.  Since the accounts don't exist any more and don't have an MFA token, they fail.  So, I setup an event handler on the FAZ to get the source IP when a user without a token tries to login.  However, it won't let me configure this as an automation stitch so I can use it on the FGT.

 

And yes...I'm already in the process of moving away from SSL VPN to IPSEC, but need SSL for a while yet during the migration.

 

2 replies

filiaks1
Explorer III
January 4, 2026

I assume the fortitoken failed MFA logs are seen in the FortiAuthenticator and send to the FortiAnalyzer. If you have the license fortianalyzer also has playbooks that you can tr Playbooks | FortiAnalyzer 7.6.5 | Fortinet Document Library

sisrayilov
Staff
February 10, 2026

This article can be helpful in case of debugging purpose to clarify the possible cause: 
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-check-why-automation-stitch-is-not-working/ta-p/190010

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!