Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gwaihir
New Contributor III

MISP feeds to FortiGate

Hello 

 

Hi Community, please I want to know if anyone has integrated misp feeds to Fortigate (I already have feeds for IP and URL from other sources)

 

How can I consume this IOC from misp events.?

 

Thank you!

 

Regards.

2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

 

I may found the answer to your question about how to consume IOCs from MISP events in FortiGate:

  1. Integrate FortiGate with MISP: Configure the integration between FortiGate and MISP to establish communication and data exchange.
  2. Import IOCs: Set up a process to import IOCs from MISP events into FortiGate. This can involve creating custom feeds or utilizing existing threat intelligence feeds within FortiGate.
  3. Update Security Policies: Use the imported IOCs to update your security policies in FortiGate. This ensures that your network security measures are aligned with the latest threat intelligence from MISP.
  4. Monitor and Respond: Continuously monitor the IOCs from MISP in FortiGate and set up automated responses or alerts to react promptly to any identified threats.
Anthony-Fortinet Community Team.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors