I traffic that is being blocked by a Fortigate because it is matching a malicious URL in the Intrusion Preventions malicious URL list:
Blocking Malicious URLs
To use this IPS signature to block malicious URLs, select Block malicious URLs. This feature uses a local malicious URL database on the FortiGate to assist in drive-by exploits detection. The database contains all malicious URLs active in the last one month, and all drive-by exploit URLs active in the last three months. The number of URLs controlled are in the one million range.
Ref: https://help.fortinet.com...e%20IPS%20scanning.htm
However, the logs do not actually log the URL that was matched. Is there anyway to actually see these URLs? I have gone into the CLI and enabled extended-logging for the Intrusion Prevention security profile, but this only added the user agent string to the logs.
Just for reference, here is part of the log type that I am referring to:
type="utm",subtype="ips",eventtype="malicious-url",msg="URL blocked by malicious-url-list"
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Checking my own IPS logs (from FortiAnalyzer) the malicious URL log entries do include the host and url, of the form:
attack=malicious-url eventtype=malicious-url hostname=www.theblacklist.click url=/g3nnn/quake3-textures.html
Do you have "Resolve Hostnames" turned on in Log Settings? See https://kb.fortinet.com/kb/viewContent.do?externalId=FD40598&sliceId=1.
tanr wrote:Do you have "Resolve Hostnames" turned on in Log Settings? See https://kb.fortinet.com/kb/viewContent.do?externalId=FD40598&sliceId=1.
thanks for replying to my post. unfortunately this would not help me for these alerts as the destination IP is a cloud proxy service we use. besides, your log examples shows you are getting more than just a reverse DNS lookup as you have the URL's path after the hostname.
can you confirm the "type" and "subtype" of this log example?
type="utm",subtype="ips"
Yes, for that same log enter: type=utm subtype=ips.
Pulling that from the raw logs on the FortiAnalyzer under Security > Intrusion Prevention.
On your FortiGate do you have both
config log gui-display set resolve-host enable end and config log setting set resolve-ip enable end
I believe you need the second one to get the actual host/url added to the log, if the FortiGate has it.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.