Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Potato
New Contributor III

How can we use FAZ playbook to create dynamic objects and block them from Fortigate?

Hi all,

 

I m trying to achieve one thing:

 

We find many SSH access to our Fortigate.

But for some reason, we can not use manual local policy or Trust hosts to prevent those attacks.

 

We have a FAZ and it seems the Playbook might work for this case.

 

We would like to :

 

1. When the FAZ finds the FGT event login failed more than 3 three times, create an object for that attacker Ip.
2. Fortigate put that object to a Firewall and both local policy for blocking

 

Can any one show me few samples if we can achieve it this way?

 

Thanks in advance!

 

 

3 REPLIES 3
Stephen_G
Moderator
Moderator

Hello Potato,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen - Fortinet Community Team
Stephen_G
Moderator
Moderator

Hello again Potato,

 

I talked to one of our engineers, and it unfortunately sounds like what you're thinking of is not currently possible. Because FortiAnalyzer as intended a logging tool, it cannot directly affect policies in FortiGate. As a result, FortiGate policies cannot be created/altered when playbook events are triggered in FortiAnalyzer.

 

I'm sorry we couldn't help more. Feel free to reach out if you have any further questions.

 

Kind regards,

Stephen - Fortinet Community Team
srajeswaran
Staff
Staff

You may try a python script similar to the one in following discusssion - https://community.fortinet.com/t5/Support-Forum/Automation-SSL-VPN-login-fail-event-gt-Ban-IP/m-p/25...

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

Labels
Top Kudoed Authors