Skip to content
Playbook Connectors on Content Hub

Fleet-wide IP blocking with a FortiManager threat feed

Creates an IP threat feed on FortiManager and keeps it filled with malicious indicators raised by FortiNDR and FortiEDR alerts.

@ftnt-dspilleMaintainer v1.0.1 Platform 7.4.0+ Published Oct 6, 2026 Updated Oct 6, 2026
Download JSON · 55 KB

fortimanager-threat-feed-blocking-1.0.1.json

sha256:e3de212edf1565e6b12f194f7744f55951e2fe373c693e5d5a0277342f690234

Sanitized by the pipeline and shipped inactive. Follow the before turning it on.

Blocks malicious IPs across every FortiGate that a FortiManager manages, using an IP threat feed that FortiManager hosts.

  1. 00 Setup - Create FMG IP Threat Feed (run once): creates the resource file and the IP threat feed (external resource) in your ADOM, and stores the names in the global variable FMG_Feed_Data.
  2. Add entries to IP Threat feed: collects every indicator marked Malicious and writes the list into the feed file. FortiGates that reference the feed in a policy pick up the change on their next refresh.
  3. Triggers that feed it:
    • Automated Block FortiNDR Destination IP: on a new FortiNDR Cloud alert, creates a malicious indicator for a public destination IP and updates the feed.
    • Manual Block FortiNDR Destination IP: the same, from a button on the alert.
    • Watch IOC's from FortiEDR: on a new FortiEDR alert (the example filter matches powershell.exe, so adjust it), creates the indicator and updates the feed.

Needs the FortiManager JSON-RPC connector. Edit the ADOM, feed name and file name in the setup playbook's Set variables step, then reference the feed as an address in a FortiGate policy.

Something wrong with this item? Sign in to report

Report a problem

Sensitive data, copied content, broken imports, anything that shouldn't be here.

At least 10 characters. Please don't paste the sensitive value itself.0/1000