Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor II

Ban ip in ips

Hello

I have ips enabled for protecting our web servers and sometimes I see attacks . So how can i automatically block attacker ip when they attack?

Reza F.
Reza F.
3 REPLIES 3
ozkanaltas
Contributor III

Hello @rezafathi ,

 

You can use quarantine action in the IPS profile. Also, you can determine quarantine time in this action. 

 

image.png

 

If you want to get more information about configuring IPS profile, you can review this document.

 

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/583477/configuring-an-ips-se...

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
KumarV
Staff
Staff

Hello, @rezafathi 

 

You can use the KB mentioned below. You will be able to create a automation stitch which would automatically add the rouge IP's in a group and then you can use that group in a firewall policy to block the access.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Permanently-block-rogue-IPs-from-accessing...

 

Regards

 

Verender

LunarEcho
New Contributor II

Setting up automatic IP blocking can definitely help ease the burden. One option is using tools like fail2ban or ModSecurity with custom rules to detect and block suspicious activity.

Labels
Top Kudoed Authors