Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
maxwell635
New Contributor

Block Malicious IP automatically

Hello guys, im trying to find a solution in order to block malicious ip automatically via an api solution or something else. Does anyone ever done something like this? What i am thinking is to create an external connection an push an api from there but i am not an expert in terms of api stuff and will take some time to figure out things. If anyone ever done something similar in a more easily way please share your thoughts

All help appreciated.

router login 192.168.l.l
1 REPLY 1
mobileitm
New Contributor

Hi maxwell,

 

Maybe not the same thing you want, but you can use External Connectors on a Fortigate applicance. If you have an active web filtering licence and any chance to publish a website which contains suspicious URL's or IP addresses (here is a sample https://www.usom.gov.tr/url-list.txt), then on your FGT go to Security Fabric > External Connectors > Create New. Under Threat Feeds select Domain Name or IP Address (your URL must contain FQDNs for Domain Name, or IPs for IP Address). When you select Domain Name, fill the Name and URL of external resource (https://www.usom.gov.tr/url-list.txt is the sample) and switch on or off HTTP basic authentication (depends on your URL's requirement of authentication) then click OK. When you finished the configuraiton, go to Security Profiles > Web Filter. Create new or update an existing one. Enable FortiGuard Category Based Filter if it is disabled. Under Remote Categories you will see the external connector you have just added. Change the Action field to Block and then save it. At the end, update Firewall Policies you want to apply this filter and enable Web Filtering select the Web Filter you have just customized.

I hope it will be useful for your purposes.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors