Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MORAMADAN
New Contributor III

Fortinet recommended malicious IPs or URLs, or Malware Hash source

Hello Team,

                 I am paloalto more guy and I used to utilize Paloalto's EDLs, so I wanted to ask about any Dynamic group that contains Malicious IP addresses, URLs, or domain lists that are included in the FortiOS and I can use them in my policies.

If not, what are recommeded other sources "feeds" to add as External groups as feed that I can use for more protection in my policies?

or also any  Malware Hash feeds that are valuable.

TIA                  

M.Ramadan
M.Ramadan
1 Solution
AEK
SuperUser
SuperUser

Hello Ramadan

Go to menu Policy & Objects > Internet Service Database, you find all bad IP address DBs under the "IP Reputation DB" section. You can use them in policy depending on their direction, as source, destination or both.

ISDB_IP_Reputation.png

AEK

View solution in original post

AEK
10 REPLIES 10
MORAMADAN
New Contributor III

thank you for the info, useful.

M.Ramadan
M.Ramadan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors