Created on 12-27-2024 12:22 AM Edited on 12-30-2024 01:40 AM By Jean-Philippe_P
Description | This article describes how to block local network communication to Botnet IPs and Botnet Domains. |
Scope | FortiGate. |
Solution |
If a LAN PC or IOT device is compromised, it will generate traffic or try to communicate with Botnet IPs and Botnet domains to take instructions or to perform certain tasks.
To check the specific details from CLI, use the below commands:
ghost-kvm35 # dia autoupdate versions | grep -A5 "Botnet" Internet service database includes Botnet C&C IP information. The current FortiGuard database version details are available at: Anti-Botnet Services.
If the database is not updated, verify the FortiGuard connectivity and run the below command to get the latest updates from the FortiGuard server.
execute update-now
config dnsfilter profile Edit the IPS profile, under Botnet C&C, and set Scan Outgoing Connections to Botnet Sites to Block.
CLI commands to apply the setting: config ips sensor Apply the DNS filter IPS profile in the FortiGate IPv4 policy, which allows the DNS service and Internet access to the local network.
date=2024-10-01 time=07:45:35 eventtime=1727793935152332727 tz="-0700" logid="1501054601" type="utm" subtype="dns" eventtype="dns-response" level="warning" vd="root" policyid=1 srcip=172.31.195.2 srcport=60981 sdstip=8.8.8.8 dstport=53 dstcountry="United States" dstintf="port1" dstintfrole="undefined" proto=6 profile="default" xid=24839 qname="iksamen.com" qtype="A" qtypeval=1 qclass="IN" ipaddr="208.91.112.55" msg="Domain was blocked by dns botnet C&C" action="redirect" botnetdomain="iksamen.com"
date=2024-10-01 time=07:26:55 eventtime=1727792815627592077 tz="-0700" logid="0422016400" type="utm" subtype="ips" eventtype="botnet" level="warning" vd="root" msg="Botnet C&C Communication." severity="critical" srcip=172.31.195.2 srccountry="Reserved" dstip=1.123.37.68 dstcountry="Australia" srcintf="port4" srcintfrole="undefined" dstintf="port1" dstintfrole="undefined" sessionid=53335 action="dropped" srcport=60798 dstport=80 proto=6 service="HTTP" policyid=1 poluuid="1170843e-7ffa-51ef-661c-df6d52a217d3" policytype="policy" profile="default" direction="outgoing" attack="NanoCore" attackid=7630215 ref="http://www.fortinet.com/be?bid=7630215" crscore=50 craction=4 crlevel="critical" |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.