Skip to main content
40chris
New Member
January 20, 2025
Question

how to disable specific ip address in ISDB

  • January 20, 2025
  • 3 replies
  • 1276 views

There is a nice article
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-Disable-Specific-IP-Addresses-or-IP-Address/ta-p/271410
but this does not really help, if you want to disable an entry in the Malicious-Server table.
Because this has more than 500.000 entries and if the ip-address is in the middle you can scroll down a few weeks.
Not possible to search for the ip-address and disable it.

3 replies

kafikar1
New Member
January 20, 2025

Just create an loopback interface with a ip address. (Can be a /32) Change the sslvpn interface to the loopback interface you just created. Then go to vips and create a VIP with your external IP Address and forward it to your loopback ip address.

ebilcari
Staff
Staff
January 20, 2025

If you want to have a search bar in the GUI, I would suggest to reach your local Fortinet representative and ask for a New Feature Request.

For now you can try the CLI approach 'config firewall internet-service-extension' as shown in this article.

Emirjon
AEK
SuperUser
SuperUser
January 20, 2025

Another approach is to add a firewall rule to the specific IP just before the ISDB related rule, in order to allow or deny the traffic to that IP address before it is matched by the ISDB related rule.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!