FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
wcruvinel
Staff
Staff
Article Id 332310
Description

This article describes what happens when a WAN IP/Public IP address is on a blacklist and how this can affect the ability to send emails, access websites, and maintain online reputation, and steps will be provided to help with checking the WAN IP, identifying if it is blacklisted, and resolve and prevent these issues.

Scope FortiGate.
Solution

How to find a WAN IP/Public IP address on FortiGate:

  1. Access the FortiGate Web Interface: Check WAN IP/Public IP details in the dashboard if possible. Example here.
  2. Another way to find the public IP address is by using the following website: https://api.ipify.org

Example below:

 

public_wan.png

 

How to Check if the  WAN/Public IP is Blacklisted:

  1. Find the IP: Get the WAN/Public IP address.
  2. Visit a Blacklist Checker:
  3. Enter the IP: Type the IP address into the search box and hit enter.
  4. View Results: The tool will check the IP against multiple blacklists and show the results, indicating if the IP is flagged and by which blacklists.

Example below:

 

blacklist.PNG

 

Consequences of a Blacklisted WAN IP:

  1. Email Issues:
    • Blocked Emails: Emails might bounce back because servers reject them when the IP is blacklisted.
    • Spam Folder: Even if delivered, emails could land in the recipient's spam folder, making them easy to miss.
  2. Website Access Problems:
    • Blocked Sites: Some websites might be blocked entirely, showing a '403 Forbidden' error, preventing access to important services.
    • Business Impact: This can cause delays, and missed opportunities, and potentially hurt the overall competitiveness and profitability of the company by damaging customer relationships and leading to a loss of market share.
    • Trust Issues: A blacklisted IP can make the network seem risky, damaging your reputation and complicating business relationships.
    • Marketing Problems: Blacklisting can lower your website’s search ranking and prevent marketing emails from reaching customers.

How to Fix and Prevent IP Blacklisting:

  1. Check Regularly: Use tools like https://multirbl.valli.org/ and https://www.fortiguard.com/services/antispam to see if the IP is blacklisted. Catching it early is key.
  2. Get Off the List: If blacklisted, contact the provider to remove it. Explain the issue is fixed.
  3. Fix the Problem: Identify what caused the blacklist, like a compromised device or email server issue, and resolve it.
  4. Contact Your ISP: If issues persist, ask the ISP for help, like assigning a new IP.
  5. Enhance Security: Upgrade the network security with better firewalls, anti-malware, and monitoring to avoid future blacklisting.

Conclusion:

  1. Having a WAN/Public IP on a blacklist can cause problems for the network and the business. Being aware of the risks and regularly checking IP status, it is possible to avoid problems. Keep an eye on the IP and fix any issues quickly to stay in the clear.

 

Related articles:

Technical Tip: Checking and reviewing blacklisted WAN IP

Technical Tip: How to remove WAN IP from blacklist