Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mhrth
New Contributor III

Questions Regarding SolarWinds-SpamExperts

Hi!

 

I recently discovered this Internet Service while going through the Source.

 

Would like to know what is the purpose of this? Is it related to Spam databases and should we block it?

 

Really appreciate the communities' assistance on this.

 

mhrth_0-1667974997031.png

 

1 Solution
sidewaysguy14

Hey there mhrth, 

 

That would be the ISDB object for the SW SPam Experts services and would be the object with all of the associated IPs and ports for that service.  This can be used in a variety of ways with policies in different places in FortiOS.  

 

If it's being used in an active policy, it may be good to sort out why it is there or who used it.  Is the Solar Winds service something that your company uses?  I wouldn't block unless you had a specific reason for traffic not to ingress or egress from those IPs associated in the object. 

 

The ISDB Reputation Database objects also can be used for effective deny policies though, and you may want to have a look at them.  

 

https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/849970/internet-services 

Secure all the things!

View solution in original post

3 REPLIES 3
sidewaysguy14

Hey there mhrth, 

 

That would be the ISDB object for the SW SPam Experts services and would be the object with all of the associated IPs and ports for that service.  This can be used in a variety of ways with policies in different places in FortiOS.  

 

If it's being used in an active policy, it may be good to sort out why it is there or who used it.  Is the Solar Winds service something that your company uses?  I wouldn't block unless you had a specific reason for traffic not to ingress or egress from those IPs associated in the object. 

 

The ISDB Reputation Database objects also can be used for effective deny policies though, and you may want to have a look at them.  

 

https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/849970/internet-services 

Secure all the things!
mhrth
New Contributor III

We did not use any of SW services and I thought this will help us to block any spam emails coming in to our company if we put in the incoming policy.

 

Anyway, thanks! really appreciate your feedback :D

sidewaysguy14

No problem at all!  

 

Have a look at the ISDB Rep DB entries as using the Botnet/Malicious/Phishing entries as top global deny policies would also help either for inbound server VIPs or for blocking traffic from external bound traffic from users clicking on things in emails.  :) 

Secure all the things!
Top Kudoed Authors