Created on 05-27-2024 09:42 PM Edited on 01-16-2025 01:41 AM By Jean-Philippe_P
Description |
This article describes how to resolve issues with external threat feed objects not showing any valid entries when the FortiGate is successfully loading the feed. |
Scope | FortiGate. |
Solution |
For external threat feeds (IP address/domain/MAC address/Malware hash) where the feed is loading a text file hosted on an external web server, the feed may display no valid entries when the file loads successfully.
Example IP address threat feed experiencing the issue:
The external text file is viewable and valid when viewed in a web browser:
This error can be caused due to the file being saved in a text encoding other than UTF-8. The file will load successfully from the external server, but the text will not be parsed correctly and loaded into an object that can be used on the FortiGate.
To View the list in CLI :
diag sys external-address-resource list
To correct the issue, ensure that the file loaded by the FortiGate is UTF-8 text encoded. The entries will then load correctly: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.