Created on 03-20-2023 11:12 PM Edited on 09-17-2024 05:38 AM By Anthony_E
Description |
This article explains how to block the below over Internet Server Database:
The ISDB objects mentioned are currently available only for IPv4. In other words, IPv6 objects are not available for the specified list at this time. If there is a requirement for IPv6 support, contact the local Fortinet Sales representative to submit a New Feature Request (NFR). |
Scope | FortiGate. |
Solution |
Internet service Database has 2 fields:
Threat sites can be blocked by setting a minimum reputation value on the firewall policy over CLI or by using IP reputation in the internet service database. Using the internet service database gives us the advantage of using more specific categories on the firewall policy
In the below example, an outbound block rule has been configured to stop potential threat websites:
Block Logs:
Refer to the below article to set the minimum reputation value on the firewall policy: Technical Tip: IP reputation in policies and fallthrough
Note: The above is only applicable to outbound policy. For inbound policy keep isdb on the source and destination address 'all', action deny -> policy keep on top and also enable match vip on policy with the below command set match-vip enable Refer to the below article for enabling match-vip on the policy: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.