Dear All,
How to block malicious IPs using the external threat option.
Here I am new I don't know to create an external server for those IPs. If anyone has an Idea please let me know.
As It is not possible to block 5000 IPs in a single or multiple policies for me.
Regards,
Umesh
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Creating 5000 address objects is not a good idea Fortigate performance-wise. As you correctly noticed, you have external feeds for that, but to use this feature you have to have some external server (managed by you or by threat list provider) that will host this IP list in a text format downloadable by the Fortigate via HTTP. You cannot manually import list of IPs to the Fortigate as is.
I wrote short post with screenshots on how to do so, you may find helpful: https://yurisk.info/2020/08/08/fortigate-using-external-threat-feeds-and-ip-domain-block-lists/
Hi Yuri,
I wanted to know how creat it on servers, Actually I don't have any Idea could you please guide me
Thank you
In general terms:
# last updated 1595753401 (Sun Jul 26 08:50:01 2020 GMT)
0.0.0.0/8
5.44.248.0/21
5.57.208.0/21
5.172.176.0/21
3. You create External Threat Feed in the fortigate that you point to the URL http://10.10.10.11/blocklist.txt , then use it in the rules.
I have found below youtube from where I have seen how to do it-
https://www.youtube.com/watch?v=iudWn16Dxus
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.