Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
blason
New Contributor

Can we roll out 5000 null routes at a moment?

Hi Guys,

 

I need to know if we can roll out or script bulk routing. That is I need to add certain malicious IPs may be 5000/6000 in numbers and need to add null route for those to block.

2 REPLIES 2
ede_pfau
SuperUser
SuperUser

hi,

 

that depends on your hardware and the version of FortiOS used.

For example, http://help.fortinet.com/fgt/54/max-values/5-4-6/max-values.html shows the hardcoded limits for "static routes" as 500 for a 100D, 10.000 for a 600D. Same limits apply for FOS v5.6.3 (but this is not always the case).

 

You can check the currently implemented value on your hardware as well.

Type "print tablesize" in the CLI, and look for the line containing "router.static". 'grep' unfortunately doesn't work in this context.

 

Using (and maintaining!) 5.000 blackhole routes is cumbersome to say the least. Why not trust FortiGuard botnet and malicious sites' IP lists which are updated continuously?

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
emnoc
Esteemed Contributor III

Agreed, managing   BH-routes or address group is not  effective.

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors