What version of fortiOS and I have to say your mistaken. Under every version of ForiOS you have some type or quarantine setting in 5.2GA it' s even simple as american pie
config ips sensor
edit " ips_sen01D0001"
set comment " prevent ips attacks"
config entries
edit 1
set severity medium high critical
next
edit 2
set rule 29027
set status enable
set action block
set quarantine attacker <----here
set quarantine-expiry 1200 <---here
set rate-count 200
set rate-duration 10 <---here
set rate-track src-ip < set the track dst or src here
next
The reason why I say to quarantine is you don' t have todo anything manually like;
add blackhole routes
remove blackhole ( when the attackers die off )
reduce falase positives
or block somebody by accident and forget about them
That' s why I say quarantine there butts is way better, simple and is 3 clicks or less for configurations.
I leave you with two thoughts;
1> would your rather keep monitor your logs and adding/removing entries in the blackholes
or
2> configure your 1 ips HRTBLEED entry and forget about it
Your call, but #2 is what I would do.
I' ve built exact this using the snort fox signatures and don' t even both to look at it other than monitoring my ips alerts.
Also I geo block most of the attackers sources by countries that I have zero need for and like 90-95% of these attacks died off the 1st day.