{"id":1589,"date":"2021-06-29T15:51:12","date_gmt":"2021-06-29T19:51:12","guid":{"rendered":"https:\/\/increasec.com\/?p=1589"},"modified":"2024-06-26T11:01:59","modified_gmt":"2024-06-26T15:01:59","slug":"use-spamhaus-threat-feeds-with-fortigate","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=1589","title":{"rendered":"Use SpamHaus threat feeds with Fortigate"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">SpamHaus is a well known service that keeps a curated downloadable list of Internet offenders.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">to see a link to the list https:\/\/www.spamhaus.org\/drop\/<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"917\" height=\"641\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image.png\" alt=\"\" class=\"wp-image-1590\" style=\"width:488px;height:341px\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image.png 917w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-300x210.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-768x537.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-100x70.png 100w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-710x496.png 710w\" sizes=\"auto, (max-width: 917px) 100vw, 917px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You can see the DROP list and EDROP list in the left column<br>just for reference these are<br>https:\/\/www.spamhaus.org\/drop\/drop.txt<br>https:\/\/www.spamhaus.org\/drop\/edrop.txt<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Logon to your Fortigate firewall and navigate to Security Fabric, External Connectors and click Create New<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"561\" height=\"345\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-5.png\" alt=\"\" class=\"wp-image-1595\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-5.png 561w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-5-300x184.png 300w\" sizes=\"auto, (max-width: 561px) 100vw, 561px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Scroll to the bottom and choose FortiGuard Category,   under Threat Feeds<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"562\" height=\"414\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-2.png\" alt=\"\" class=\"wp-image-1592\" style=\"width:363px;height:267px\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-2.png 562w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-2-300x221.png 300w\" sizes=\"auto, (max-width: 562px) 100vw, 562px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Enter a Name, paste your link copied from above, no auth is required, and set a reasonable refresh rate<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"637\" height=\"473\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-3.png\" alt=\"\" class=\"wp-image-1593\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-3.png 637w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-3-300x223.png 300w\" sizes=\"auto, (max-width: 637px) 100vw, 637px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Now in Security Profiles, Web Filter you can see the lists that were added under Remote Categories heading.  They default to Disabled and they need to be set to Block or Warning to be effective.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"828\" height=\"479\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-4.png\" alt=\"\" class=\"wp-image-1594\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-4.png 828w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-4-300x174.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-4-768x444.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/06\/image-4-710x411.png 710w\" sizes=\"auto, (max-width: 828px) 100vw, 828px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the Fortinet filters have expired there is another way to do this.  Turn off the FortiGuard Category based filters and enable an External IP Block list.  I had to create the block list again as it wouldn&#8217;t let me re-use an existing one.  <br>https:\/\/www.spamhaus.org\/drop\/drop.txt<br>WARNING Spamhaus is in the process of replacing this .TXT list with a .json list which is not supported by Fortinet firewalls v7.2.x   may be supported on later versions.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"883\" height=\"643\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2024\/06\/Filter.png\" alt=\"\" class=\"wp-image-2953\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2024\/06\/Filter.png 883w, https:\/\/increasec.com\/wp-content\/uploads\/2024\/06\/Filter-300x218.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2024\/06\/Filter-768x559.png 768w\" sizes=\"auto, (max-width: 883px) 100vw, 883px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>SpamHaus is a well known service that keeps a curated downloadable list of Internet offenders. to see a link to the list https:\/\/www.spamhaus.org\/drop\/ You can see the DROP list and&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[75,4],"class_list":["post-1589","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-forinet","tag-security"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/1589","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1589"}],"version-history":[{"count":6,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/1589\/revisions"}],"predecessor-version":[{"id":2956,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/1589\/revisions\/2956"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1589"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1589"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}