Hi All,
We have to block around 5000 public IP in FortiGate firewall 1200D, actually, I got a security advisory for this from our organization.
Just I would like to know from you all if there is any flexible solution for it as you know that this is a very lengthy task for me as we have to block one by one IP.
let me give an example -
Source IP would be - 193. X.X.X
Destination - 11.X.X.X
service - any and port no 449 also
blocked.
Thank you in advance.
you would have to generate the cli script from e.g. a list of ips and then run that on cli or imort it via gui. I don't know any other way.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Well,
Could you please describe how to do it and what is the method and also pls write here the steps on how to do in FortiGate 1200D.
Thank you for replying on it.
Hi,
If the IP list can be maintained on a server, FG can be configured to pull the IP list from the server by adding an external thread feed. If this option interests you, you can have a look at the below link:
Some time ago I've developed a Python script to create a FortiOS blacklist from a simple list of IPs. You can find it here
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1110 | |
758 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.