Skip to main content

Setup guide

FortiGate threat feed of malicious IPs and domains, with basic authentication

FortiOS sends HTTP basic authentication with each threat feed request, so the FortiGate downloads the full isMalicious list itself, with nothing to relay. Block the IPs in firewall policies and the domains in a DNS filter.

No credit card required · Free API key

Data path
  1. isMalicious

    api.ismalicious.com

    blocklist-ips-critical.txt

    Rebuilt every 12 h

  2. FortiGate

    Step 2

    Create the IP feed

  3. Deny the feed in firewall policies

    Step 4
On this page08

What you get

Up to FortiOS 7.4.3 a feed holds 131,072 entries or 10 MB; from 7.4.4 one budget per entry type covers every feed, 300,000 IPs on the smallest models. Every list below fits each release and model.

ListEntriesRebuiltPlans
blocklist-ips-critical.txtDefault IP feed. IPs listed by 6 or more threat sources, or 3 or more with a critical category.about 89,000every 12 hBasic, Pro, and Enterprise
blocklist-ips-critical50k.txtThe 50,000 critical IPs with the highest risk score, highest first: leaves room when other IP feeds share the 7.4.4+ budget.50,000, cappedevery 12 hBasic, Pro, and Enterprise
blocklist-ips-c2.txtCommand-and-control IPs reported by C2 trackers, whatever their level.about 44,000every 12 hBasic, Pro, and Enterprise
blocklist-domains-c2.txtDefault domain feed, for the DNS filter: command-and-control domains reported by C2 trackers.about 22,000every 12 hBasic, Pro, and Enterprise
blocklist-domains-ransomware.txtDomains in the ransomware category, whatever their level.about 3,600every 12 hBasic, Pro, and Enterprise
blocklist-domains-cryptomining.txtDomains in the cryptomining category, whatever their level.about 6,100every 12 hBasic, Pro, and Enterprise

Entries rounded from the build of ; each list is rebuilt every 12 hours. Today’s counts are public and need no key.

What each plan receives

  • FreeFree account, or no key: the first 10% of each list, marked X-Blocklist-Version: lite.
  • Basic, Pro, and EnterpriseBasic, Pro, and Enterprise: every list in full.
  • Pro and EnterpriseTAXII 2.1 collections, for platforms that read STIX indicators: Pro and Enterprise.

Compare plans

What a download returnsHTTP

GET https://api.ismalicious.com/blocklist/download/blocklist-ips-critical.txt

Full list or 10% sample

FieldBasic, Pro, and EnterpriseFree
X-Blocklist-Version:fulllite
X-Blocklist-Percentage:10010
Total entries:<COUNT><COUNT> (Lite Version - 10% of <TOTAL>)

First lines of the file

# IsMalicious.com Blocklist - IPs (Critical)
# Format: Plain
# Generated: <BUILD_TIME>
# Total entries: <COUNT>
# Update frequency: every 12 hours
# Category: All
# Threat level: Critical
# Website: https://ismalicious.com
# © <YEAR> IsMalicious (compilation). Licensed to the downloading account under https://ismalicious.com/terms; redistribution of the compilation prohibited. Third-party entries remain under their providers' licences — see https://ismalicious.com/sources.
#

Values in angle brackets are set by each build.

Prerequisites

  • FortiOS 7.0.8, 7.2.4 or later, the first builds that can verify a feed server’s certificate (the check is off by default). Avoid 7.4.5 to 7.4.8 and 7.6.1 to 7.6.3, which fail that check on threat feeds; 7.4.9 and 7.6.4 fix it.
  • If management traffic must leave by a given interface, set interface-select-method specify and interface, or source-ip, on the external resource.
  • For the domain feed only: a FortiGuard Web Filter license, which category-based DNS filtering requires.
  • An isMalicious API key and secret, from Account › API access.
  • Outbound HTTPS (TCP 443) over IPv4 from FortiGate to api.ismalicious.com, which has no IPv6 address.

Set it up

  1. Copy your API key and secret

    Open Account › API access and copy the API Key and the API Secret. The full list needs a Basic, Pro, or Enterprise plan; a Free key, or a lapsed plan, loads the 10% sample.
  2. Create the IP feed

    • Security Fabric › External Connectors › Create New, then External Feeds › IP Address from 7.6.1, Threat Feeds › IP Address on 7.0 to 7.6.0.
    • Name it isMalicious-IPs, keep Update method on External Feed where the field is shown, paste the list URL in URL of external resource (URI of external resource on 7.0 and 7.2), set Refresh Rate to 60 minutes, and click OK.
    • In the GUI, save the connector with HTTP basic authentication off, run the certificate block of the next step, then turn on HTTP basic authentication with the API key as Username and the API secret as Password: FortiOS fetches the feed as soon as it is saved, and the check is off until then.
    • The CLI block sets both in one commit.
    IP feed (CLI)FortiOS
    config system external-resource
      edit "isMalicious-IPs"
        set type address
        set resource "https://api.ismalicious.com/blocklist/download/blocklist-ips-critical.txt"
        set username "<API_KEY>"
        set password "<API_SECRET>"
        set refresh-rate 60
        set server-identity-check full
      next
    end
  3. Turn on certificate checking

    If you created the feed in the GUI, set the check in the CLI: FortiOS does not verify the feed server’s certificate by default (server-identity-check none), and Fortinet documents the setting in the CLI only. Set it to full, which also checks the host name. Without it, the API secret travels over TLS that a man in the middle could terminate.
    Certificate checkFortiOS
    config system external-resource
      edit "isMalicious-IPs"
        set server-identity-check full
      next
    end
  4. Deny the feed in firewall policies

    • Policy & Objects › Firewall Policy › Create New: Destination isMalicious-IPs (in the IP ADDRESS FEED section), Action DENY, logging on, for outbound traffic.
    • Add a second policy with the feed as Source for inbound traffic, with match-vip enabled when servers are reached through VIPs (no GUI field; the default from 7.2.4): a regular deny policy does not block VIP traffic.
    • An SD-WAN member cannot be a policy interface: use its zone.
    • In the CLI, edit 0 takes the next free policy ID and adds the policy at the bottom, under the allow policies, where it never matches: move both above them with the move block.
    Deny policiesFortiOS
    config firewall policy
      edit 0
        set name "isMalicious-outbound"
        set srcintf "<LAN_INTERFACE>"
        set dstintf "<WAN_INTERFACE>"
        set srcaddr "all"
        set dstaddr "isMalicious-IPs"
        set action deny
        set schedule "always"
        set service "ALL"
        set logtraffic all
      next
      edit 0
        set name "isMalicious-inbound"
        set srcintf "<WAN_INTERFACE>"
        set dstintf "<LAN_INTERFACE>"
        set srcaddr "isMalicious-IPs"
        set dstaddr "all"
        set action deny
        set schedule "always"
        set service "ALL"
        set logtraffic all
        set match-vip enable
      next
    end
    
    # edit 0 adds each policy at the bottom. Read the two new IDs at the end of
    # "show firewall policy", then put them above the policies that allow the traffic:
    config firewall policy
      move <OUTBOUND_ID> before <FIRST_LAN_TO_WAN_ALLOW_ID>
      move <INBOUND_ID> before <FIRST_WAN_TO_LAN_ALLOW_ID>
    end
  5. Protect the FortiGate itself (optional)

    From FortiOS 7.2.4 and 7.4.0, a local-in policy can use the IP feed as its source, to drop traffic aimed at the FortiGate’s own interfaces.
    Local-in policyFortiOS
    config firewall local-in-policy
      edit 0
        set intf "<WAN_INTERFACE>"
        set srcaddr "isMalicious-IPs"
        set dstaddr "all"
        set action deny
        set service "ALL"
        set schedule "always"
      next
    end
  6. Block the domains with a DNS filter (optional)

    • Create New › Domain Name in the same connector menu, with the same fields and blocklist-domains-c2.txt as the URL; in the CLI, category 192, or the next unused number up to 221, and server-identity-check full.
    • Then Security Profiles › DNS Filter: edit the profile, enable FortiGuard Category Based Filter, set the feed to Redirect to Block Portal under Remote Categories, then apply the profile where your clients’ DNS queries pass: in the accept policy that lets LAN clients reach DNS servers (a deny policy carries no profile), or, if clients use the FortiGate as their resolver, under Network › DNS Servers › DNS Service on Interface › DNS Filter (in the CLI, config system dns-server, then edit on the LAN interface and set dnsfilter-profile).
    Domain feed (CLI)FortiOS
    config system external-resource
      edit "isMalicious-Domains"
        set type domain
        set category 192
        set resource "https://api.ismalicious.com/blocklist/download/blocklist-domains-c2.txt"
        set username "<API_KEY>"
        set password "<API_SECRET>"
        set refresh-rate 60
        set server-identity-check full
      next
    end

Verify it works

  • Edit the connector: once the file loads it shows its last update and how many entries it holds, and View Entries lists them.
  • diagnose sys external-resource stats prints, per feed, the total, valid and error lines and, from 7.4.4, buildable, the entries loaded under the limit. Valid lines should be close to the list’s count in /blocklist/stats, and buildable equal to them.
  • The REST monitor API returns the feed’s entries and status: GET /api/v2/monitor/system/external-resource/entry-list?mkey=isMalicious-IPs&status_only=true.
  • Denied sessions appear in the logs of the two policies; blocked domains under Log & Report › Security Events › DNS Query (Log & Report › DNS Query on 7.0).
  • About a tenth of the published count means the 10% sample. The FortiGate does not show the file’s header: the forticron debug shows X-Blocklist-Version: lite in the response, or a curl from a workstation with the same key shows Lite Version in the Total entries line.
CLI checksFortiOS
# Per feed: total, valid and error lines; from 7.4.4 also buildable, the
# entries loaded under the limit.
diagnose sys external-resource stats

# Watch one download: the request, its Authorization header (your credential,
# in base64: keep it out of tickets), the X-Blocklist-Version answer and the
# TLS result.
diagnose debug reset
diagnose debug application forticron -1
diagnose debug console timestamp enable
diagnose debug enable
# Reload the feeds now rather than waiting for the next refresh:
diagnose test application forticron 8
# ...then:
diagnose debug disable
diagnose debug reset

Troubleshooting

The feed shows a connection error after a 401

The key or the secret is wrong or incomplete. FortiOS keeps the previous file, so the old list stays in force. The response body reads “Blocklist not found or empty”; trust the status code. Copy both values again from Account › API access: regenerating the key there invalidates the old pair.

Only about 10% of the entries load

No credential reached the server, because the authentication toggle is off or a field is empty, or the plan is Free or lapsed: past due, unpaid, canceled, incomplete or paused counts as Free. The forticron debug shows X-Blocklist-Version: lite in the response.

buildable below valid lines, or no Entries field

The per-feed or the global entry limit is reached. Pick a smaller list from the table above, or reorder the feeds with move: from 7.4.4, entries past the budget are not loaded.

A timeout or a 502 on a large list

A download that takes longer than 30 seconds on our side ends in a timeout or a 502: use a tier or category list from the table.

503 Service Unavailable

The list is being built, and the response carries Retry-After: 600. FortiOS keeps its previous file and the next refresh picks the list up.

Error lines in the feed statistics

The # header lines are comments to FortiOS. Error lines mean the URL points at a format FortiOS does not read: use the plain file, not an -adguard or -hosts one.

“Server not reachable” with certificate checking on

On 7.4.5 to 7.4.8 and 7.6.1 to 7.6.3, this is a FortiOS bug with server-identity-check on threat feeds: upgrade to 7.4.9 or 7.6.4. Do not unset the check instead: the secret would then go to an unverified server. api.ismalicious.com uses a Let’s Encrypt certificate, renewed about every 60 days.

403 from ismalicious.com

The ismalicious.com edge refuses some sources. Use api.ismalicious.com, the host meant for appliances.

Limits

  • blocklist-domains-critical.txt, about 2 million domains, overflows the per-feed limit up to 7.4.3 and the entry-level budget from 7.4.4; only mid-range and high-end models on 7.4.4 or later can hold it, and only on 7.4.8 or 7.6.4 and later, since a domain feed over 1 million entries in a flow-based policy exhausts the IPS engine’s memory before them. The lists are unsorted, so a truncated load is an arbitrary subset.
  • From 7.4.4 the entry budget is shared by every feed of the same type: another vendor’s IP feed uses the same allowance.
  • No CIDR or ranges are served: FortiOS accepts them, but the IP lists hold single addresses.
  • Existing sessions are re-evaluated after the shorter of the refresh rate and 30 minutes.
  • The domain path needs the FortiGuard Web Filter license. If the license lapses, FortiOS can no longer rate domains and, by default, drops all DNS through the profile: turn on Allow DNS requests when a rating error occurs (config ftgd-dns, set options error-allow) if DNS must fail open. Without the license, use the IP feeds.
  • FortiOS lists STIX as a feed protocol. The isMalicious TAXII server has not been tested with it: use the lists.
  • The 10% sample is the first tenth of an unsorted file, not the riskiest tenth.

Questions

Does FortiGate send an API key for an external threat feed?

Yes. Turn on HTTP basic authentication on the feed, available since FortiOS 6.2.0: the API key is the username, the API secret the password. FortiOS sends them with the first request, so the firewall receives the full list with no relay. Send them only from 7.0.8 or 7.2.4, with server-identity-check set to full: earlier releases cannot verify the server’s certificate.

How many entries can a FortiGate threat feed hold?

Up to FortiOS 7.4.3, 131,072 entries or 10 MB per feed. From 7.4.4, one budget per entry type covers every feed: 300,000 IPs on every model until 7.4.8 and 7.6.2, then 300,000 on entry-level, 1 million on mid-range and 5 million on high-end models from 7.4.9 and 7.6.3.

Why set server-identity-check?

Its default is none: FortiOS does not verify the feed server’s certificate, so the API secret could go to a man in the middle. Set it to full. On 7.4.5 to 7.4.8 and 7.6.1 to 7.6.3, upgrade to 7.4.9 or 7.6.4 first: those builds fail the check on threat feeds.

What refresh rate should the feed use?

60 minutes. The lists are rebuilt every 12 hours and the responses carry Cache-Control: max-age=3600. When a refresh fails, FortiOS keeps the previous file.

Can a FortiGate block the domain lists?

Yes, as a Domain Name feed used as a remote category in a DNS filter profile, which needs a FortiGuard Web Filter license. Use the C2, ransomware or cryptomining domain lists: the critical domain list only fits mid-range and high-end models on 7.4.4 or later, and only on 7.4.8 or 7.6.4 and later.

Get Started

Ready to get started?

No credit card required · Free API key