跳到主要內容

發表文章

目前顯示的是有「UTM」標籤的文章

Fortigate IPS, DNS/WEB Filter, Domain & IP Reputation

 Fortigate 啟用 Fortigate IPS, DNS/WEB Filter, Domain & IP Reputation 相關功能 在 Fortigate 要使用一些功能,必須先到[Feature Visibility] 中啟用該功能。 DNS Filter Apply DNS category filtering, URL filtering to control user's access to web resources. Set up DNS Filter Profiles (Security Profiles > DNS Filter) and add them to Firewall Policies or add them to a DNS Server on a FortiGate interface. Some features require a subscription to FortiGuard Web Filtering. Web Filter Apply web category filtering, URL filtering, and content filtering to control user's access to web resources. Set up Web Filter Profiles (Security Profiles > Web Filter) and add them to Firewall Policies. Some features require a subscription to FortiGuard Web Filtering. 前兩項 ,個人認為比較偏向 Client (Outgoing),避免去到惡意的網站或網址 Domain & IP Reputation Enable the Reputation Lookup feature. This page allows querying of reputations for IPs or FQDNs as classified in FortiGuard databases. Databases require a valid FortiGuard subscription. Int...

External Block List (Threat Feed)

如何建立外部的 IP 封鎖清單 # Explame Paltfrom: Fortigate 20xE / 6.2.11 Ref: Fortigate Threat feeds(6.2.x) Ref: External Block List (Threat Feed) – Policy(6.2.0)   Ref: All Cybercrime IP Feeds by FireHOL [Security Fabric] → [Fabric Connectors]  → [Create New] → [IP Address] 以 [https://raw.githubusercontent.com/ktsaou/blocklist-ipsets/master/firehol_level1.netset] 為 List 來源 在 Policy 引用 (記得 Block Deny Policy 要在前面) 建議搭配 [Intrusion Prevention]及其Block [Botnet C&C]、DNS Filter、Web Filter