Created on
05-21-2020
08:49 AM
Edited on
05-12-2023
05:47 AM
By
Anthony_E
Description
FortiOS version V6.2 onwards the external block list (threat Feed) in firewall policy can be done.
In addition to using the external block list for web filtering and DNS, use it in firewall policies.
This article describes how to use the external block list.
Solution
This version includes the following new features:
1) Policy support for external IP list used as source/destination address.
2) Support for IPv4 and IPv6 firewall policy only. ACL, DoS, NAT64, NAT46, shaping, local-in policy are not supported.
3) Support for both CLI and GUI.
Configuration.
Go to Security Fabric -> Fabric Connectors -> Threat Feeds -> IP Address, create or edit an external IP list object.
# config system external-resourceTo apply an external IPlist object to the firewall policy using the CLI.
edit "test-external-iplist-1"
set status enable
set type address
set username ''
set password ENC
set comments ''
set resource "http://100.100.100.100/ip_list_test/test-external-iplist-2.txt"
set refresh-rate 15
next
end
# config firewall policyResults.
edit 1
set name "policyid-1"
set srcintf "wan2"
set dstintf "wan1"
set srcaddr "all"
set dstaddr "test-external-iplist-1"
set action accept
set schedule "always"
set service "ALL"
set logtraffic all
set auto-asic-offload disable
set nat enable
next
The content of external feed can be monitored with the following API query:
https://x.x.x.x/api/v2/monitor/system/external-resource/entry-list/USOM/?
access_token=Hnb9ccdd17y10xnp7zn1mjtwkQ0nwN where 'USOM' is the name of the external threat feed.
This API query will show both content of the feed and the latest status of feed update.
In case of a communication issue, the API query will report the status as 'error' similar to the
Following example :
The following URL will provide only the status of the External connector without the content of it :
https://x.x.x.x/api/v2/monitor/system/external-resource/entry-list/USOM?status_only=true
Remark: In case of communication issues, FortiGate does not receive the updates but preserves the original file.
Below are the steps for configuring windows pc as an external server for Thread feed:
1.Navigate to start and search for Turn windows features on or off.
2.Enable IIS(Internet Information service)
3.Navigate to the following path in pc C:\inetpub\wwwroot
4.Create a text file and add entries to that file.
5.Configure the URI link as http://<IP address of PC>/<filename.txt> on fortigate firewall.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.