FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Dongkwan
Staff
Staff
Article Id 258042
Description

This article describes that only four types (FortiGuard Category, IP Address, Domain Name, and Malware Hash) were available through the threat feeds feature before the 7.4.0 version. The Mac address type has been added after the 7.4.0 version.

Scope

FortiGate v7.4.0 later.

Solution

There are 5 types of Threat Feeds after the 7.4.0 version:

1) FortiGuard Category.
2) IP Address.
3) Domain Name.
4) MAC Address.
5) Malware Hash.

 

GUI menu to view the type of Threat Feeds:

Security Fabric -> External Connectors -> Threat Feeds.

 

gui_mac_Address.JPG

 

CLI commands to view the type of Threat Feeds.

 

config system external-resource
    edit "mac address"
        set type
category FortiGuard category.
address Firewall IP address.
domain Domain Name.
malware Malware hash.
mac-address Firewall MAC address.

 

Once created the MAC External Threat Feed, it is possible to use it in the Firewall Policy as below :

 

MAC-Policy.png