Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

KalanaChandrasiri
New Contributor

Firewall Rules for SIEM Implementation

Dear People,

We need to knnow exact URL/IP address what FortiSIEM get feeds from Outside (Internet) ? According our environment we cannot open full internet access to device. We only allowed to give specific IP/URL.

Note - The port definition sheet on external data source configuration is not clearly mentioed these details.


Where We can get these details any link/official document ?


Regards,
Kalana


------------------------------
kalana
------------------------------
1 Solution
FSM_FTNT
Staff
Staff

It depends on what services you are using.

To access the OS repo:

https://os-pkgs-cdn.fortisiem.fortinet.com/centos6/
https://os-pkgs.fortisiem.fortinet.com/centos6/


If you are using FortiGuard IOC feed with FSM you will need to allow access as well to:

https://update.fortiguard.net
https://fds1.fortinet.com

Any other threat feeds configured or lookups, you will also need to allow access to them. For example Whois, VirusTotal, RiskIQ, etc.

View solution in original post

3 REPLIES 3
FSM_FTNT
Staff
Staff

It depends on what services you are using.

To access the OS repo:

https://os-pkgs-cdn.fortisiem.fortinet.com/centos6/
https://os-pkgs.fortisiem.fortinet.com/centos6/


If you are using FortiGuard IOC feed with FSM you will need to allow access as well to:

https://update.fortiguard.net
https://fds1.fortinet.com

Any other threat feeds configured or lookups, you will also need to allow access to them. For example Whois, VirusTotal, RiskIQ, etc.

KalanaChandrasiri

Daniel,
Thank you very much for your feedback.

May I know what is the URL/IP for FortiSIEM License activation is done ?


Regards,
Kalana
FSM_FTNT

Hi Kalana,

This is a manual download of the license and then upload in the ForitSIEM GUI.

Thanks

Dan