Fortinet Fortigate NGFW DBL Configuration Guide

Submit a Ticket

To continue with this configuration guide you must first Submit a ticket via the Samurai MDR application. Add the following information within your Ticket:

Ticket fieldInformation
TitleDBL Onboarding Request for Fortinet Fortigate device(s)
DescriptionAdd hostname and IP address (internet facing) of your Fortinet Fortigate devices. For example: acmegw1.acme.org, 19.16*.2*.2 If enrolling multiple devices please add each device on individual lines

Submit the ticket and you will hear back from us with additional information (e.g DBL URL) to continue with the configuration below.

Connection Requirements

You will need to ensure your Fortigate device(s) can reach a specific URL to obtain the DBL. This information will be provided to you once subscribed.

ParameterNote
Connection PortTCP / 443
DBL URLNTT will provide a unique URL to you to download the DBL URL list

Table 1: Connections requirements

To complete this integration you have to:

  • Have submitted a ticket via the SamurAi portal and have been provided the necessary DBL endpoint URL/IP address.

From your Fortinet Fortigate Devices or FortiManager:

Create a Threat Feed External Connector for URL DBL

  1. Follow the Fortinet documentation FortiGuard category external feed. The linked documentation outlines an example, however use the following parameters when creating the feed:

highlight.png We link the FortiGate / FortiOS 8.0.0 Administration Guide therefore you may need to refer to additional Fortinet documentation.

ParameterEntry
Threat Feed TypeSelect FortiGuard Category
Namewhatever you want, we recommend SamuraiMDR_URL_DBL
URL of external resourceFeed URL will be provided to you upon enablement of the add-on (ensure you have raised a request)
HTTP basic authenticationdisable
Refresh Ratewe recommend 10 minutes
Commentsoptional
StatusEnable
  1. Verify the threat feed has been created and is updating successfully by checking its Status and Last update fields in Security Fabric > External Connectors, and by using View Entries to see the current list.

Create a Web Filter

  1. Follow the steps outlined in the same linked Fortinet documentation under the section entitled To apply a FortiGuard category external feed in a web filter profile using the following parameters:
ParameterEntry
Namewhatever you want, we recommend Webfilter_for_SamuraiMDR_URL_DBL
Commentsoptional
Feature setConfigure as required for your environment*
FortiGuard Category Based Filterenable
Remote CategorySelect the feed created in the previous section, we recommend SamuraiMDR_URL_DBL
ActionBlock
Other parametersset all other parameters as required or leave as default

Apply the Web Filter to a Firewall Policy

  1. Follow the steps outlined in the same linked Fortinet documentation under the section entitled To apply the web filter profile in a firewall policy using the following parameters:

highlight.png You may also want to refer to the additional Fortinet documentation - Firewall policy.

ParameterEntry
IDoptional
Namewhatever you want, we recommend Policy_for_SamuraiMDR_URL_DBL
Incoming Interfaceset according to your environment
Outgoing Interfaceset according to your environment
Sourceall (recommended)
Destinationall (recommended)
Schedulealways (recommended)
Serviceall (recommended)
Inspection Modefeature set set in previous section
Security Profilesselect the profile you created in the previous section, we recommend Webfilter_for_SamuraiMDR_URL_DBL
SSL Inspectionoptional based on your environment
Logging Options/Log allowed trafficSecurity events
Advancedenable this policy
Other parametersset all other parameters as required or leave as default

Create a Threat Feed External Connector for IP DBL

  1. Follow the Fortinet documentation IP address external feed. The linked article outlines an example, however use the following parameters when creating the feed:
ParameterEntry
Threat Feed TypeSelect IP Address
Namewhatever you want, we recommend SamuraiMDR_IP_DBL
URI of external resourceFeed URI will be provided to you upon enablement of the add-on (ensure you have raised a request)
HTTP basic authenticationdisable
Refresh Ratewe recommend 10 minutes
Commentsoptional
StatusEnable
  1. You can verify the threat feed has been created and view entries by following the View Entries step in the Fortinet documentation.

Apply the IP DBL to a Firewall Policy

  1. Follow the steps outlined in the same linked Fortinet documentation under the section entitled To apply an IP address external feed in a firewall policy using the following parameters:

highlight.png You may also want to refer to the additional Fortinet documentation - Firewall policy.

ParameterEntry
IDoptional
Namewhatever you want, we recommend Policy_for_SamuraiMDR_IP_DBL
Incoming Interfaceset according to your environment
Outgoing Interfaceset according to your environment
Sourceall (recommended)
Destinationselect the feed created in the previous section, we recommend SamuraiMDR_IP_DBL
Schedulealways (recommended)
Serviceall (recommended)
ActionDeny
Log violation trafficoptional (enable to log)
Advancedenable this policy
Other parametersset all other parameters as required or leave as default
  1. Ensure to set the firewall policy according to your environment and ensure the DENY policy is effective, also setting the Policy_for_SamuraiMDR_IP_DBL at higher order than Policy_for_SamuraiMDR_URL_DBL.

Our Dynamic Block List (DBL) configuration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by Submitting a ticket in the Samurai MDR application and we shall get it updated.