Created on
06-27-2023
12:11 AM
Edited on
09-22-2025
12:59 AM
By
Jean-Philippe_P
| Description | This article describes how to verify, prevent, and take action on a malicious IP address not blocked by IP Reputation. |
| Scope | FortiWeb. |
| Solution |
FortiWeb leverages IP reputation as a critical defense mechanism, analyzing the past activities of IP addresses to identify and block potentially malicious traffic. By mitigating risks associated with web application vulnerabilities, DDoS attacks, and unauthorized access attempts, FortiWeb's IP reputation feature empowers organizations to strengthen their security posture.
Navigate to System -> Config -> FortiGuard:
Subsequently, verify the latest database version release on the FortiGuard website:
Navigate to IP Protection -> IP Reputation:
By default, FortiWeb takes action against a poor IP address’s reputation by ‘Block Period’ for 60 seconds.
Navigate to IP Protection -> IP List
Related document: IP List - Blocklisting & whitelisting clients using a source IP or source IP range
Threat actors may use IP addresses that are not updated in the latest IP Reputation DB. In such cases, a request can be submitted to FortiGuard to re-evaluate the IP address. FortiWeb Application Security Contact Form
Refer to the FortiWeb Administrator Guide for more information regarding IP Reputation: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.