- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate support for STIX/TAXII
Hello experts,
Does Fortigate support STIX/TAXII for receiving / pulling threat intelligence?
If yes, what versions of STIX/TAXII are supported?
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi experts,
Can anyone help respond to this.
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
there is no support for STIX / TAXII in fortigate firewalls.
Only the FortiSandbox supports STIX and TAXII.
Best Regards
bommi
NSE 4/5/7
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for the answer.
Is STIX/TAXII support by any chance in roadmap in order to pull threat intelligence from other sandboxes?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi SmackIT,
the feature is called "Fabric Connectors":
You need the "Fabric Connector for threat feeds" part of this documentation.
In FortiOS 6.0 only IP- and Domainlists are supported, in FortiOS 6.2 which is currently beta you can also import Hashlists.
Best Regards
bommi
NSE 4/5/7
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I don't know.
Fortigate firewalls can pull threat intelligence information from webservers.
You can import lists of IP-Addresses, Domains and Filehashes and use this information in the webfilter, dnsfilter and av-filter.
Regards bommi
NSE 4/5/7
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Bommi,
Can you please point me to the related document / KB for doing this?
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
this feature is called "Fabric Connector":
You need the "Fabric Connector for threat feeds" part of this documentation.
In FortiOS 6.0 only IP- and Domainlists are supported, in FortiOS 6.2 which is currently Beta you can also import Hashlists.
Best Regards
bommi
NSE 4/5/7
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Bommi.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
