- Home
- Integrations
- FortiGate
Setup guide
FortiGate threat feed of malicious IPs and domains, with basic authentication
No credit card required · Free API key
On this page
On this page08
What you get
Up to FortiOS 7.4.3 a feed holds 131,072 entries or 10 MB; from 7.4.4 one budget per entry type covers every feed, 300,000 IPs on the smallest models. Every list below fits each release and model.
| List | Entries | Rebuilt | Plans |
|---|---|---|---|
| blocklist-ips-critical.txtDefault IP feed. IPs listed by 6 or more threat sources, or 3 or more with a critical category. | about 89,000 | every 12 h | Basic, Pro, and Enterprise |
| blocklist-ips-critical50k.txtThe 50,000 critical IPs with the highest risk score, highest first: leaves room when other IP feeds share the 7.4.4+ budget. | 50,000, capped | every 12 h | Basic, Pro, and Enterprise |
| blocklist-ips-c2.txtCommand-and-control IPs reported by C2 trackers, whatever their level. | about 44,000 | every 12 h | Basic, Pro, and Enterprise |
| blocklist-domains-c2.txtDefault domain feed, for the DNS filter: command-and-control domains reported by C2 trackers. | about 22,000 | every 12 h | Basic, Pro, and Enterprise |
| blocklist-domains-ransomware.txtDomains in the ransomware category, whatever their level. | about 3,600 | every 12 h | Basic, Pro, and Enterprise |
| blocklist-domains-cryptomining.txtDomains in the cryptomining category, whatever their level. | about 6,100 | every 12 h | Basic, Pro, and Enterprise |
Entries rounded from the build of ; each list is rebuilt every 12 hours. Today’s counts are public and need no key.
What each plan receives
- FreeFree account, or no key: the first 10% of each list, marked
X-Blocklist-Version: lite. - Basic, Pro, and EnterpriseBasic, Pro, and Enterprise: every list in full.
- Pro and EnterpriseTAXII 2.1 collections, for platforms that read STIX indicators: Pro and Enterprise.
GET https:/
Full list or 10% sample
| Field | Basic, Pro, and Enterprise | Free |
|---|---|---|
X-Blocklist-Version: | full | lite |
X-Blocklist-Percentage: | 100 | 10 |
Total entries: | <COUNT> | <COUNT> |
First lines of the file
# IsMalicious.com Blocklist - IPs (Critical)
# Format: Plain
# Generated: <BUILD_TIME>
# Total entries: <COUNT>
# Update frequency: every 12 hours
# Category: All
# Threat level: Critical
# Website: https://ismalicious.com
# © <YEAR> IsMalicious (compilation). Licensed to the downloading account under https://ismalicious.com/terms; redistribution of the compilation prohibited. Third-party entries remain under their providers' licences — see https://ismalicious.com/sources.
#Values in angle brackets are set by each build.
Prerequisites
- FortiOS 7.0.8, 7.2.4 or later, the first builds that can verify a feed server’s certificate (the check is off by default). Avoid 7.4.5 to 7.4.8 and 7.6.1 to 7.6.3, which fail that check on threat feeds; 7.4.9 and 7.6.4 fix it.
- If management traffic must leave by a given interface, set
interface-select-methodandspecify interface, orsource-ip, on the external resource. - For the domain feed only: a FortiGuard Web Filter license, which category-based DNS filtering requires.
- An isMalicious API key and secret, from Account › API access.
- Outbound HTTPS (TCP 443) over IPv4 from FortiGate to
api.ismalicious.com, which has no IPv6 address.
Set it up
Copy your API key and secret
Open Account › API access and copy the API Key and the API Secret. The full list needs a Basic, Pro, or Enterprise plan; a Free key, or a lapsed plan, loads the 10% sample.Create the IP feed
- Security Fabric › External Connectors › Create New, then External Feeds › IP Address from 7.6.1, Threat Feeds › IP Address on 7.0 to 7.6.0.
- Name it
isMalicious-IPs, keep Update method on External Feed where the field is shown, paste the list URL in URL of external resource (URI of external resource on 7.0 and 7.2), set Refresh Rate to60minutes, and click OK. - In the GUI, save the connector with HTTP basic authentication off, run the certificate block of the next step, then turn on HTTP basic authentication with the API key as Username and the API secret as Password: FortiOS fetches the feed as soon as it is saved, and the check is off until then.
- The CLI block sets both in one commit.
IP feed (CLI)FortiOS config system external-resource edit "isMalicious-IPs" set type address set resource "https://api.ismalicious.com/blocklist/download/blocklist-ips-critical.txt" set username "<API_KEY>" set password "<API_SECRET>" set refresh-rate 60 set server-identity-check full next endTurn on certificate checking
If you created the feed in the GUI, set the check in the CLI: FortiOS does not verify the feed server’s certificate by default (server-identity-check none), and Fortinet documents the setting in the CLI only. Set it tofull, which also checks the host name. Without it, the API secret travels over TLS that a man in the middle could terminate.Certificate checkFortiOS config system external-resource edit "isMalicious-IPs" set server-identity-check full next endDeny the feed in firewall policies
- Policy & Objects › Firewall Policy › Create New: Destination
isMalicious-IPs(in the IP ADDRESS FEED section), Action DENY, logging on, for outbound traffic. - Add a second policy with the feed as Source for inbound traffic, with
match-vipenabled when servers are reached through VIPs (no GUI field; the default from 7.2.4): a regular deny policy does not block VIP traffic. - An SD-WAN member cannot be a policy interface: use its zone.
- In the CLI,
edit 0takes the next free policy ID and adds the policy at the bottom, under the allow policies, where it never matches: move both above them with themoveblock.
Deny policiesFortiOS config firewall policy edit 0 set name "isMalicious-outbound" set srcintf "<LAN_INTERFACE>" set dstintf "<WAN_INTERFACE>" set srcaddr "all" set dstaddr "isMalicious-IPs" set action deny set schedule "always" set service "ALL" set logtraffic all next edit 0 set name "isMalicious-inbound" set srcintf "<WAN_INTERFACE>" set dstintf "<LAN_INTERFACE>" set srcaddr "isMalicious-IPs" set dstaddr "all" set action deny set schedule "always" set service "ALL" set logtraffic all set match-vip enable next end # edit 0 adds each policy at the bottom. Read the two new IDs at the end of # "show firewall policy", then put them above the policies that allow the traffic: config firewall policy move <OUTBOUND_ID> before <FIRST_LAN_TO_WAN_ALLOW_ID> move <INBOUND_ID> before <FIRST_WAN_TO_LAN_ALLOW_ID> end- Policy & Objects › Firewall Policy › Create New: Destination
Protect the FortiGate itself (optional)
From FortiOS 7.2.4 and 7.4.0, a local-in policy can use the IP feed as its source, to drop traffic aimed at the FortiGate’s own interfaces.Local-in policyFortiOS config firewall local-in-policy edit 0 set intf "<WAN_INTERFACE>" set srcaddr "isMalicious-IPs" set dstaddr "all" set action deny set service "ALL" set schedule "always" next endBlock the domains with a DNS filter (optional)
- Create New › Domain Name in the same connector menu, with the same fields and
blocklist-domains-c2.txtas the URL; in the CLI, category 192, or the next unused number up to 221, andserver-identity-check full. - Then Security Profiles › DNS Filter: edit the profile, enable FortiGuard Category Based Filter, set the feed to Redirect to Block Portal under Remote Categories, then apply the profile where your clients’ DNS queries pass: in the accept policy that lets LAN clients reach DNS servers (a deny policy carries no profile), or, if clients use the FortiGate as their resolver, under Network › DNS Servers › DNS Service on Interface › DNS Filter (in the CLI,
config system dns-server, thenediton the LAN interface andset dnsfilter-profile).
Domain feed (CLI)FortiOS config system external-resource edit "isMalicious-Domains" set type domain set category 192 set resource "https://api.ismalicious.com/blocklist/download/blocklist-domains-c2.txt" set username "<API_KEY>" set password "<API_SECRET>" set refresh-rate 60 set server-identity-check full next end- Create New › Domain Name in the same connector menu, with the same fields and
Verify it works
- Edit the connector: once the file loads it shows its last update and how many entries it holds, and View Entries lists them.
diagnoseprints, per feed, the total, valid and error lines and, from 7.4.4,sys external-resource stats buildable, the entries loaded under the limit. Valid lines should be close to the list’scountin /blocklist/stats, andbuildableequal to them.- The REST monitor API returns the feed’s entries and status:
GET./ api/ v2/ monitor/ system/ external-resource/ entry-list? mkey= isMalicious-IPs& status_only= true - Denied sessions appear in the logs of the two policies; blocked domains under Log & Report › Security Events › DNS Query (Log & Report › DNS Query on 7.0).
- About a tenth of the published count means the 10% sample. The FortiGate does not show the file’s header: the forticron debug shows
X-Blocklist-Version: litein the response, or acurlfrom a workstation with the same key showsLite Versionin theTotal entriesline.
# Per feed: total, valid and error lines; from 7.4.4 also buildable, the
# entries loaded under the limit.
diagnose sys external-resource stats
# Watch one download: the request, its Authorization header (your credential,
# in base64: keep it out of tickets), the X-Blocklist-Version answer and the
# TLS result.
diagnose debug reset
diagnose debug application forticron -1
diagnose debug console timestamp enable
diagnose debug enable
# Reload the feeds now rather than waiting for the next refresh:
diagnose test application forticron 8
# ...then:
diagnose debug disable
diagnose debug resetTroubleshooting
The feed shows a connection error after a 401
The key or the secret is wrong or incomplete. FortiOS keeps the previous file, so the old list stays in force. The response body reads “Blocklist not found or empty”; trust the status code. Copy both values again from Account › API access: regenerating the key there invalidates the old pair.
Only about 10% of the entries load
No credential reached the server, because the authentication toggle is off or a field is empty, or the plan is Free or lapsed: past due, unpaid, canceled, incomplete or paused counts as Free. The forticron debug shows X-Blocklist-Version: lite in the response.
buildable below valid lines, or no Entries field
The per-feed or the global entry limit is reached. Pick a smaller list from the table above, or reorder the feeds with move: from 7.4.4, entries past the budget are not loaded.
A timeout or a 502 on a large list
A download that takes longer than 30 seconds on our side ends in a timeout or a 502: use a tier or category list from the table.
503 Service Unavailable
The list is being built, and the response carries Retry-After: 600. FortiOS keeps its previous file and the next refresh picks the list up.
Error lines in the feed statistics
The # header lines are comments to FortiOS. Error lines mean the URL points at a format FortiOS does not read: use the plain file, not an -adguard or -hosts one.
“Server not reachable” with certificate checking on
On 7.4.5 to 7.4.8 and 7.6.1 to 7.6.3, this is a FortiOS bug with server-identity-check on threat feeds: upgrade to 7.4.9 or 7.6.4. Do not unset the check instead: the secret would then go to an unverified server. api.ismalicious.com uses a Let’s Encrypt certificate, renewed about every 60 days.
403 from ismalicious.com
The ismalicious.com edge refuses some sources. Use api.ismalicious.com, the host meant for appliances.
Limits
blocklist-domains-critical., about 2 million domains, overflows the per-feed limit up to 7.4.3 and the entry-level budget from 7.4.4; only mid-range and high-end models on 7.4.4 or later can hold it, and only on 7.4.8 or 7.6.4 and later, since a domain feed over 1 million entries in a flow-based policy exhausts the IPS engine’s memory before them. The lists are unsorted, so a truncated load is an arbitrary subset.txt - From 7.4.4 the entry budget is shared by every feed of the same type: another vendor’s IP feed uses the same allowance.
- No CIDR or ranges are served: FortiOS accepts them, but the IP lists hold single addresses.
- Existing sessions are re-evaluated after the shorter of the refresh rate and 30 minutes.
- The domain path needs the FortiGuard Web Filter license. If the license lapses, FortiOS can no longer rate domains and, by default, drops all DNS through the profile: turn on Allow DNS requests when a rating error occurs (
config ftgd-dns,set options error-allow) if DNS must fail open. Without the license, use the IP feeds. - FortiOS lists STIX as a feed protocol. The isMalicious TAXII server has not been tested with it: use the lists.
- The 10% sample is the first tenth of an unsorted file, not the riskiest tenth.
Questions
Does FortiGate send an API key for an external threat feed?
Yes. Turn on HTTP basic authentication on the feed, available since FortiOS 6.2.0: the API key is the username, the API secret the password. FortiOS sends them with the first request, so the firewall receives the full list with no relay. Send them only from 7.0.8 or 7.2.4, with server-identity-check set to full: earlier releases cannot verify the server’s certificate.
How many entries can a FortiGate threat feed hold?
Up to FortiOS 7.4.3, 131,072 entries or 10 MB per feed. From 7.4.4, one budget per entry type covers every feed: 300,000 IPs on every model until 7.4.8 and 7.6.2, then 300,000 on entry-level, 1 million on mid-range and 5 million on high-end models from 7.4.9 and 7.6.3.
Why set server-identity-check?
Its default is none: FortiOS does not verify the feed server’s certificate, so the API secret could go to a man in the middle. Set it to full. On 7.4.5 to 7.4.8 and 7.6.1 to 7.6.3, upgrade to 7.4.9 or 7.6.4 first: those builds fail the check on threat feeds.
What refresh rate should the feed use?
60 minutes. The lists are rebuilt every 12 hours and the responses carry Cache-Control: max-age=3600. When a refresh fails, FortiOS keeps the previous file.
Can a FortiGate block the domain lists?
Yes, as a Domain Name feed used as a remote category in a DNS filter profile, which needs a FortiGuard Web Filter license. Use the C2, ransomware or cryptomining domain lists: the critical domain list only fits mid-range and high-end models on 7.4.4 or later, and only on 7.4.8 or 7.6.4 and later.
Related
External Dynamic Lists sized to PAN-OS limits
A URL Table alias or pfBlockerNG feed through a relay
URL Table aliases with Basic authorization
Threat domains as a RouterOS DNS adlist
Threat IPs as nftables sets on any Linux host
Keep firewall blocklists current
Every list, level and category
TAXII 2.1 collections for SIEMs and TIPs
Authentication, endpoints and limits
Check one address before you block it
Get Started
Ready to get started?
No credit card required · Free API key