Created on
02-07-2025
04:09 AM
Edited on
08-07-2025
02:10 AM
By
Jean-Philippe_P
Description | This article describes how to check if an IP is malicious on the FortiGuard site. |
Scope | FortiGate, FortiGuard. |
Solution |
In this article, an example IP of 167.94.138.41 is used.
Navigate to the following URL. Note the inclusion of 'engine=7'.
The indication of engine 7 means that the Options Field is set to IP/Domain/URL, as shown in the screenshot below.
https://www.fortiguard.com/search?q=167.94.138.41&engine=7
Example screenshot:
In this example, the IP is tagged as Malicious under Web Filtering, Antispam, IOC, and IP Geolocation.
IP lookups can be done from the FortiGate as well. Navigate to Policy & Object -> Internet Service Database -> IP Address Lookup.
Put the IP, and it will show its reputation.
Below is the command that can be used to search ISDB for specific IP addresses:
diagnose internet-service match <vdname> <ip> <netmask>
Note: Reuse the keyword field and check for IPs that are suspected to be Malicious.
If the IP address is not found or is not categorized correctly, send a submission through the Malicious URL Appeal form to the FortiGuard Team for evaluation.
Related article: Technical Tip: CVE lookup and other important features in FortiGuard Labs |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.