Description | This article describes the new feature of using IP Reputation Database Objects as Source Address in Local-in policy. |
Scope | FortiOS v7.4.4+ and v7.6+. |
Solution |
IP Reputation Database are aggregated list of malicious IPs collated from various global sources by FortiGuard.
These IP Reputation Database Objects are under the Internet Service Database and can be seen under Policy & Objects -> Internet Service Database. Since FortiOS v7.4.4, FortiOS now allows internet service as source addresses in the local-in policy. This provides more flexibility and control in managing local traffic, improving network security and efficiency.
There are 8 out of 9 IP Reputation Database objects that can be used as source addresses for local-in policy namely :
Note: 'Blockchain-Crypto.Mining.Pool' despite being part of the IP Reputation Database can only be used as a destination address for policies.
In FortiOS v7.4.4+, the local-in policy can be configured via CLI ('internet-service-src' needs to be enabled) :
config firewall local-in-policy edit <id> set intf "port1" next end
In FortiOS v7.6+, local-in policies can now be configured via GUI as well :
Note: Local-in policies for Address objects cannot be mixed with Internet Service objects. Create separate policies for each. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.