Anyone ever see a Fortinet daily report get blocked due to malicious URL? I get daily reports from our fortigates and this one was blocked. This is what mimecast shows in the log. Strange is that same report, on the same day went to our helpdesk with no issue and from a totally different IP. I looked back a couple days and saw the same thing a few days ago. Did an SPF check and that 89[.]248 address is not in Fortinet's SPF record.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello David,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hey David,
I double-checked, but I was not able to confirm if the IP range in question belongs to Fortinet/FortiCloud or not. The report name does look legitimate, but the source IP is suspicious indeed. Have you submitted the report to any virus scanners for checking?
If this happens regularly, you could consider a ticket with Fortinet Support to verify if the IP is expected or not (if yes, then it should not be classed as malicious, if not, then it bears further investigating what that report actually is).
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.