FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
VinayHM
Staff
Staff
Article Id 269186
Description This article describes how to identify a threat feed by using the MAC address in the external connectors.
Scope FortiGate, FortiOS 7.4.0 and above.
Solution

In older versions of FortiOS, threat feeds use the following:

  • Domain.
  • Malware.
  • IP address.

FortiOS versions 7.4.0 and above allows for checking a threat feed by MAC address.

 

ssth.PNG

 

To use this feature:

 

  1. Go to Security Fabric -> External Connectors and select Create New.
  2. In the Threat Feeds section, select MAC Address.
  3. Set the Name to MAC_List.
  4. Set the Update method to External Feed.
  5. Set the URL of the external resource to http://X.X.X.X/external-resources/Ext-Resource-Type-as-Address-mac-1.txt.
  6. Configure the remaining settings as required, then select OK.

 

To apply a MAC address threat feed in a policy:

  1. Select a policy.
  2. In the 'source' field, select MAC list from the list.
  3. Select Apply.
Contributors