Skip to main content
zuhura2
New Member
February 24, 2026
Question

Malicious domain blocking in fortigate

  • February 24, 2026
  • 1 reply
  • 159 views

Hi Everyone.

I have been blocking malicious domain and ip using firewall policy. Recently I configured external threatfeed for ip but couldn't figure out how to do it for domains. My requirement is to call domains in source and destination of the policy for blocking.

Is there any way I can do it??

1 reply

AEK
SuperUser
SuperUser
February 24, 2026

Hi Zuhura

I think ISDB IP Reputation DB should be better than most external threat feeds.

It doesn't include DNS domains but it doesn't matter since it includes their IP addresses as source and/or destination.

AEK