FortiGate'e Tehdit İstihbarat Feed'i Nasıl Eklenir? How to Add a Threat Intelligence Feed to FortiGate
FortiOS'un External Threat Feed connector özelliğini kullanarak, SiberKapan'ın ücretsiz IP blocklist'ini firewall politikanıza nasıl ekleyeceğinizi adım adım anlatıyoruz. A step-by-step guide to adding SiberKapan's free IP blocklist to your firewall policy using FortiOS's External Threat Feed connector.
FortiOS, harici bir URL'den periyodik olarak IP veya domain listesi çeken ve bunu doğrudan firewall politikalarında kullanılabilir bir adres nesnesine dönüştüren bir "External Connector" mekanizmasına sahiptir. Bu sayede, FortiGuard'ın kendi tehdit istihbaratının yanına, SiberKapan gibi bağımsız kaynaklardan gelen ek bir katman ekleyebilirsiniz — özellikle Türkiye'ye özgü saldırı örüntüleri için değerlidir. FortiOS has an "External Connector" mechanism that periodically pulls an IP or domain list from an external URL and converts it into an address object usable directly in firewall policies. This lets you add an extra layer from independent sources like SiberKapan alongside FortiGuard's own threat intelligence — particularly valuable for attack patterns specific to Turkey.
External Connector OluşturunCreate the External Connector
FortiGate arayüzünde Security Fabric > External Connectors menüsüne gidin, Create New > Threat Feeds > IP Address seçin.In the FortiGate interface, go to Security Fabric > External Connectors, select Create New > Threat Feeds > IP Address.
Feed URL'sini GirinEnter the Feed URL
URI alanına SiberKapan'ın FortiGate CLI formatındaki feed adresini yazın:In the URI field, enter SiberKapan's FortiGate CLI format feed address:
https://siberkapan.org/api/v1/list/fortigate
Güncelleme Sıklığını AyarlayınSet the Refresh Interval
Refresh Rate alanını feed'in kendi güncelleme sıklığına yakın bir değere ayarlayın (örn. 360 dakika / 6 saat) — daha sık çekmek gereksiz yük oluşturur.Set the Refresh Rate close to the feed's own update frequency (e.g. 360 minutes / 6 hours) — polling more often just creates unnecessary load.
Firewall Politikasına EkleyinAdd It to a Firewall Policy
Oluşturduğunuz external connector artık bir adres nesnesi olarak Policy & Objects > Addresses altında görünür. Bunu ilgili firewall politikanızın Source alanına ekleyip Action: Deny yaparak trafiği engelleyin.The external connector you created now appears as an address object under Policy & Objects > Addresses. Add it to the Source field of your firewall policy and set Action: Deny to block the traffic.
İlk kurulumda politikayı Log Allowed Traffic ile izleme modunda test etmeniz, doğrudan Deny'a geçmeden önce beklenmedik bir engelleme olup olmadığını görmenizi sağlar.
On first setup, testing the policy in monitor mode with Log Allowed Traffic lets you check for unexpected blocks before switching directly to Deny.
Diğer Format SeçenekleriOther Format Options
41844 onaylı IP; TXT, JSON, CIDR ve iptables formatlarında da mevcut.41844 approved IPs, also available in TXT, JSON, CIDR, and iptables formats.