FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ekrishnan
Staff
Staff
Article Id 375284
Description This article describes how to check if an IP is malicious on the FortiGuard site.
Scope FortiGate, FortiGuard.
Solution

In this article, an example IP of 167.94.138.41 is used.

 

Navigate to the following URL. Note the inclusion of 'engine=7

 

The indication of engine 7 means that the Options Field is set to IP/Domain/URL as shown in the screenshot below.

 

https://www.fortiguard.com/search?q=167.94.138.41&engine=7

 

Example screenshot:

 

image.png

 

In this example, the IP is tagged as Malicious under Web Filtering, Antispam, IOC, and IP Geolocation.

 

IP lookup can be done from the FortiGate as well. Navigate to Policy & Object -> Internet Service Database -> IP Address Lookup

 

mali.png

 

Put the IP and it will show the reputation of it.


Screenshot 2025-02-18 102717.png

 

Note:

Reuse the keyword field and check for IPs that are suspected to be Malicious.