FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
acardona
Staff
Staff
Article Id 392395
Description This article explains a workaround to disable IP entry that is beyond 100K entries.
Scope FortiGate.
Solution

Due to the following known issue 853352, this does not allow disabling entries that are beyond 45% of the ISDB Malicous-Malicious Server.  To disable a specific entry, the following workaround can be applied:

  1. Identify the IP address that needs to be allowed; use of logs can help.
  2. Create an Address that needs to be allowed.
  3. Add this to the group Address.
  4. Create a Firewall Policy on top of the ISDB policy, create the IP and services that need to be allowed:

 

Example:

 

image (69).png

 

 

This should allow the entry that is required to be exempt from the ISDB.

 

For more information about this known issue, see this related KB article: Troubleshooting Tip: Scrolling in 'View/Edit Entries' tab is stuck for ISDB object 'Malicious-Malici... 

Contributors