Description
This article describes how to block TOR traffic from the WAN to the LAN, by using the ISDB object. This ISDB object contains a list of all TOR exit nodes currently known and is updated by FortiGuard.
Scope
FortiGate.
Solution
Go to Policy & Objects -> IPV4 Policy and select 'Create New'.
Go to Source -> Internet Service, search for 'Tor' and select 'Tor-Exit node'.
When creating the policy is finished, place it as high in the policy list.
Since policy lookup is done from top to bottom, place this policy as high as possible to prevent traffic coming from TOR to run through all the other policies above it.
Application Control can be used as well:
Blocking Tor traffic using the Application Control profile:
The references listed below on FortiGuard Labs provide additional details regarding the application control used in this article.
Tor:
https://www.fortiguard.com/appcontrol/15565
To2Web:
https://fortiguard.fortinet.com/appcontrol/30452
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.