Is it possible to create an address object on a FGT using logs from a FAC via an event handler on a FAZ?
We setup several automation stitches on the FAZ and FGT to add address objects based on failed VPN attempts. What I'm also looking to do, if possible, is create an object from a failed login attempt.
Basically, there are hosts out there throwing names and passwords at us. Since the accounts don't exist any more and don't have an MFA token, they fail. So, I setup an event handler on the FAZ to get the source IP when a user without a token tries to login. However, it won't let me configure this as an automation stitch so I can use it on the FGT.
And yes...I'm already in the process of moving away from SSL VPN to IPSEC, but need SSL for a while yet during the migration.
I assume the fortitoken failed MFA logs are seen in the FortiAuthenticator and send to the FortiAnalyzer. If you have the license fortianalyzer also has playbooks that you can tr Playbooks | FortiAnalyzer 7.6.5 | Fortinet Document Library
| User | Count |
|---|---|
| 2910 | |
| 1450 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.