Description | This article describes how to verify, prevent, and take action on malicious IP address not blocked by IP Reputation. |
Scope | FortiWeb, FortiWeb-VM. |
Solution |
FortiWeb leverages IP reputation as a critical defense mechanism, analyzing the past activities of IP addresses to identify and block potentially malicious traffic. By mitigating risks associated with web application vulnerabilities, DDoS attacks, and unauthorized access attempts, FortiWeb's IP reputation feature empowers organizations to strengthen their security posture.
Navigate to System -> Config -> FortiGuard:
Subsequently, verify the latest DB version release on the FortiGuard website:
2. IP Reputation Policy action to prevent threat actors.
Navigate to IP Protection -> IP Reputation:
By default, FortiWeb takes action against a poor IP address’s reputation by ‘Block Period’ for 60 seconds.
3. Blocklisting IP addresses manually.
Navigate to IP Protection -> IP List
Related document:
4. Submit re-evaluation request of the malicious IP address.
In such cases, a request can be submitted to FortiGuard to re-evaluate the IP address. https://www.fortiguard.com/faq/contact-web-security
Refer to FortiWeb Administrator Guide for more information regarding IP Reputation: |