- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DNS filter and dynamic group
Hello Friends,
I have DNS filter profile and applied on the internet accessing security roles.
I need "if possible" to configure what like a dynamic object group that contains all hosts that are trying to connect to any malicious domain.
is this applicable in fortios? and how please.
Fortios ver. 7.x
TIA,
- Labels:
-
DNS filter
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Ramadan
I think you can do it with automation stitch, using trigger "Compromised Host Quarantine", than as action you may write a script to add the address to the group.
Hope it helps.
Edit: Forgot to mention, for that you also need FortiAnalyzer
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That's a feature that requires advanced Network monitoring tools (SIEM).
Something similar can be done (to some extent) when a FortiAnalyzer is configured to collect logs.
You can either set up playbooks in FAZ, or set up automation stitch to trigger events based on the logs appended by FAZ:
- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you gentelmen, I think I will pass since I dont have SEIM or fortiAnalyser. at least for time being.
