Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MamunAunick
New Contributor

Need help for FortiSOAR response via firewall

I have FortiSIEM, FortiSOAR and CheckPoint firewall. Connected FortiSIEM and CheckPoint firewall with FortiSOAR through connector. Now can anyone please guide me that how can I take action from SOAR.

 

For example:

SIEM detects a brute force attempt. SOAR ingest data from SIEM. Now I want soar to take action against the attacker through checkpoint firewall. eg: block IP/block url.

FortiSOAR FortiSIEM 

2 REPLIES 2
sjoshi
Staff
Staff

Hi,

 

You can refer below article:-

https://docs.fortinet.com/document/fortisoar/7.6.0/connectors-guide/929681/introduction-to-connector...

Let us know if this helps.
Salon Raj Joshi
asolbri2
New Contributor

FortiEDR is a good choice for endpoint protection. FortiSOAR is really great product, but a big company play, or if you have the staff, SOC as a service play, not really suitable for smaller businesses due to cost and up front complexity (someone has to configure it, and maintain it). Consider who will be feeding and taking care of this before positioning. FortiAnalyzer SOCaaS might be a better play.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors