Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MORAMADAN
New Contributor III

DNS filter and dynamic group

Hello Friends,

                    I have DNS filter profile and applied on the internet accessing security roles.

I need "if possible" to configure what like a dynamic object group that contains all hosts that are trying to connect to any malicious domain.

is this applicable in fortios? and how please.

Fortios ver. 7.x

TIA,

M.Ramadan
M.Ramadan
3 REPLIES 3
AEK
SuperUser
SuperUser

Hello Ramadan

I think you can do it with automation stitch, using trigger "Compromised Host Quarantine", than as action you may write a script to add the address to the group.

Hope it helps.

Edit: Forgot to mention, for that you also need FortiAnalyzer

AEK
AEK
AlexC-FTNT
Staff
Staff

That's a feature that requires advanced Network monitoring tools (SIEM).

Something similar can be done (to some extent) when a FortiAnalyzer is configured to collect logs.
You can either set up playbooks in FAZ, or set up automation stitch to trigger events based on the logs appended by FAZ:

https://docs.fortinet.com/document/fortianalyzer/7.6.0/administration-guide/106885/playbook-template...


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
MORAMADAN
New Contributor III

Thank you gentelmen, I think I will pass since I dont have SEIM or fortiAnalyser. at least for time being.

M.Ramadan
M.Ramadan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors