Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Lucas1
New Contributor

Automate Address List with FortiAnalizer/Playbooks/Fortigate

Hi People I need to create an automation to save all the malicious addresses that the FortiAnalizer collects/analyzes and automatically save them in a group of addresses for me to block them from the firewall. I want to know if Fortigate and FortiAnalizer can do something like this. I have the FortiSOC version available if it is necessary to do it with Playbooks. The truth is that I did not find anything like that.

 

3 REPLIES 3
patelr
Staff
Staff

Hello @Lucas1 ,

 

Please review https://community.fortinet.com/t5/FortiGate/Technical-Tip-Block-SSL-VPN-failed-logins-with-an-automa.... According to this document, you can see a functionality where an automation stich can add IP addresses into a group.

 

Thanks, 
Ronak Patel

HiralShah
Staff
Staff

Hello @Lucas1 

 

You can also use threat feed to block the malicious address list.

https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/891236/ip-address-threat-fee...

 

Hiral
salmas
Staff
Staff

Hello @Lucas1 

 

You can create an event handler on FortiAnalyzer to block such failed attempt IPs.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enhance-SSL-VPN-Security-by-blocking-offen...

salmas

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors