Fortinet Fortigate NGFW DBL Configuration Guide
Submit a Ticket
To continue with this configuration guide you must first Submit a ticket via the Samurai MDR application. Add the following information within your Ticket:
| Ticket field | Information |
|---|---|
| Title | DBL Onboarding Request for Fortinet Fortigate device(s) |
| Description | Add hostname and IP address (internet facing) of your Fortinet Fortigate devices. For example: acmegw1.acme.org, 19.16*.2*.2 If enrolling multiple devices please add each device on individual lines |
Submit the ticket and you will hear back from us with additional information (e.g DBL URL) to continue with the configuration below.
Connection Requirements
You will need to ensure your Fortigate device(s) can reach a specific URL to obtain the DBL. This information will be provided to you once subscribed.
| Parameter | Note |
|---|---|
| Connection Port | TCP / 443 |
| DBL URL | NTT will provide a unique URL to you to download the DBL URL list |
Table 1: Connections requirements
To complete this integration you have to:
- Have submitted a ticket via the SamurAi portal and have been provided the necessary DBL endpoint URL/IP address.
From your Fortinet Fortigate Devices or FortiManager:
- Create a Threat Feed External Connector for URL DBL
- Create a Web Filter
- Apply the Web Filter to a Firewall Policy
- Create a Threat Feed External Connector for IP DBL
- Apply the IP DBL to a Firewall Policy
Create a Threat Feed External Connector for URL DBL
- Follow the Fortinet documentation FortiGuard category external feed. The linked documentation outlines an example, however use the following parameters when creating the feed:
We link the FortiGate / FortiOS 8.0.0 Administration Guide therefore you may need to refer to additional Fortinet documentation.
| Parameter | Entry |
|---|---|
| Threat Feed Type | Select FortiGuard Category |
| Name | whatever you want, we recommend SamuraiMDR_URL_DBL |
| URL of external resource | Feed URL will be provided to you upon enablement of the add-on (ensure you have raised a request) |
| HTTP basic authentication | disable |
| Refresh Rate | we recommend 10 minutes |
| Comments | optional |
| Status | Enable |
- Verify the threat feed has been created and is updating successfully by checking its Status and Last update fields in Security Fabric > External Connectors, and by using View Entries to see the current list.
Create a Web Filter
- Follow the steps outlined in the same linked Fortinet documentation under the section entitled To apply a FortiGuard category external feed in a web filter profile using the following parameters:
| Parameter | Entry |
|---|---|
| Name | whatever you want, we recommend Webfilter_for_SamuraiMDR_URL_DBL |
| Comments | optional |
| Feature set | Configure as required for your environment* |
| FortiGuard Category Based Filter | enable |
| Remote Category | Select the feed created in the previous section, we recommend SamuraiMDR_URL_DBL |
| Action | Block |
| Other parameters | set all other parameters as required or leave as default |
Apply the Web Filter to a Firewall Policy
- Follow the steps outlined in the same linked Fortinet documentation under the section entitled To apply the web filter profile in a firewall policy using the following parameters:
You may also want to refer to the additional Fortinet documentation - Firewall policy.
| Parameter | Entry |
|---|---|
| ID | optional |
| Name | whatever you want, we recommend Policy_for_SamuraiMDR_URL_DBL |
| Incoming Interface | set according to your environment |
| Outgoing Interface | set according to your environment |
| Source | all (recommended) |
| Destination | all (recommended) |
| Schedule | always (recommended) |
| Service | all (recommended) |
| Inspection Mode | feature set set in previous section |
| Security Profiles | select the profile you created in the previous section, we recommend Webfilter_for_SamuraiMDR_URL_DBL |
| SSL Inspection | optional based on your environment |
| Logging Options/Log allowed traffic | Security events |
| Advanced | enable this policy |
| Other parameters | set all other parameters as required or leave as default |
Create a Threat Feed External Connector for IP DBL
- Follow the Fortinet documentation IP address external feed. The linked article outlines an example, however use the following parameters when creating the feed:
| Parameter | Entry |
|---|---|
| Threat Feed Type | Select IP Address |
| Name | whatever you want, we recommend SamuraiMDR_IP_DBL |
| URI of external resource | Feed URI will be provided to you upon enablement of the add-on (ensure you have raised a request) |
| HTTP basic authentication | disable |
| Refresh Rate | we recommend 10 minutes |
| Comments | optional |
| Status | Enable |
- You can verify the threat feed has been created and view entries by following the View Entries step in the Fortinet documentation.
Apply the IP DBL to a Firewall Policy
- Follow the steps outlined in the same linked Fortinet documentation under the section entitled To apply an IP address external feed in a firewall policy using the following parameters:
You may also want to refer to the additional Fortinet documentation - Firewall policy.
| Parameter | Entry |
|---|---|
| ID | optional |
| Name | whatever you want, we recommend Policy_for_SamuraiMDR_IP_DBL |
| Incoming Interface | set according to your environment |
| Outgoing Interface | set according to your environment |
| Source | all (recommended) |
| Destination | select the feed created in the previous section, we recommend SamuraiMDR_IP_DBL |
| Schedule | always (recommended) |
| Service | all (recommended) |
| Action | Deny |
| Log violation traffic | optional (enable to log) |
| Advanced | enable this policy |
| Other parameters | set all other parameters as required or leave as default |
- Ensure to set the firewall policy according to your environment and ensure the DENY policy is effective, also setting the Policy_for_SamuraiMDR_IP_DBL at higher order than Policy_for_SamuraiMDR_URL_DBL.
Our Dynamic Block List (DBL) configuration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by Submitting a ticket in the Samurai MDR application and we shall get it updated.