Ana SayfaHome Tehdit VeritabanıThreat Database Tehdit RaporlarıThreat Reports BlogBlog
RehberlerGuides
Tehdit İstihbaratı Nedir?What Is Threat Intelligence? MISP Nedir?What Is MISP? IP Blocklist Nedir?What Is an IP Blocklist? FortiGate'e Feed EklemeAdd Feed to FortiGate Ücretsiz CTİ KaynaklarıFree CTI Resources
Veri & ListelerData & Lists
Tüm ListelerAll Lists Feed ListeleriFeed Lists USOM Domain FeedUSOM Domain Feed SiberKapan Phishing URL FeedSiberKapan Phishing URL Feed FortiGate Saldırı HaritasıFortiGate Attack Map BGP / IP SorgulaBGP / IP Lookup Malware ÖrnekleriMalware Samples
Sisteminize EkleyinAdd to Your System
🔓 Feed Ekleme Rehberi🔓 Feed Setup Guide MISP Feed TAXII 2.1 STIX 2.1 RSS CVE Feed RSS IOC Feed
Veri GönderinContribute Data
FortiGate Webhook KurulumuFortiGate Webhook Setup HoneypotKapan KurSetup HoneypotKapan Nginx Watcher KurSetup Nginx Watcher API DokümantasyonAPI Documentation
HakkındaAbout
HakkımızdaAbout Us MetodolojiMethodology BaşarılarAchievements İletişimContact
Rehber Guide

FortiGate'e Tehdit İstihbarat Feed'i Nasıl Eklenir? How to Add a Threat Intelligence Feed to FortiGate

FortiOS'un External Threat Feed connector özelliğini kullanarak, SiberKapan'ın ücretsiz IP blocklist'ini firewall politikanıza nasıl ekleyeceğinizi adım adım anlatıyoruz. A step-by-step guide to adding SiberKapan's free IP blocklist to your firewall policy using FortiOS's External Threat Feed connector.

External Threat Feed Nedir? What Is an External Threat Feed?

FortiOS, harici bir URL'den periyodik olarak IP veya domain listesi çeken ve bunu doğrudan firewall politikalarında kullanılabilir bir adres nesnesine dönüştüren bir "External Connector" mekanizmasına sahiptir. Bu sayede, FortiGuard'ın kendi tehdit istihbaratının yanına, SiberKapan gibi bağımsız kaynaklardan gelen ek bir katman ekleyebilirsiniz — özellikle Türkiye'ye özgü saldırı örüntüleri için değerlidir. FortiOS has an "External Connector" mechanism that periodically pulls an IP or domain list from an external URL and converts it into an address object usable directly in firewall policies. This lets you add an extra layer from independent sources like SiberKapan alongside FortiGuard's own threat intelligence — particularly valuable for attack patterns specific to Turkey.

Adım Adım Kurulum Step-by-Step Setup
1

External Connector OluşturunCreate the External Connector

FortiGate arayüzünde Security Fabric > External Connectors menüsüne gidin, Create New > Threat Feeds > IP Address seçin.In the FortiGate interface, go to Security Fabric > External Connectors, select Create New > Threat Feeds > IP Address.

2

Feed URL'sini GirinEnter the Feed URL

URI alanına SiberKapan'ın FortiGate CLI formatındaki feed adresini yazın:In the URI field, enter SiberKapan's FortiGate CLI format feed address:

https://siberkapan.org/api/v1/list/fortigate
3

Güncelleme Sıklığını AyarlayınSet the Refresh Interval

Refresh Rate alanını feed'in kendi güncelleme sıklığına yakın bir değere ayarlayın (örn. 360 dakika / 6 saat) — daha sık çekmek gereksiz yük oluşturur.Set the Refresh Rate close to the feed's own update frequency (e.g. 360 minutes / 6 hours) — polling more often just creates unnecessary load.

4

Firewall Politikasına EkleyinAdd It to a Firewall Policy

Oluşturduğunuz external connector artık bir adres nesnesi olarak Policy & Objects > Addresses altında görünür. Bunu ilgili firewall politikanızın Source alanına ekleyip Action: Deny yaparak trafiği engelleyin.The external connector you created now appears as an address object under Policy & Objects > Addresses. Add it to the Source field of your firewall policy and set Action: Deny to block the traffic.

İlk kurulumda politikayı Log Allowed Traffic ile izleme modunda test etmeniz, doğrudan Deny'a geçmeden önce beklenmedik bir engelleme olup olmadığını görmenizi sağlar. On first setup, testing the policy in monitor mode with Log Allowed Traffic lets you check for unexpected blocks before switching directly to Deny.

Diğer Format SeçenekleriOther Format Options

41844 onaylı IP; TXT, JSON, CIDR ve iptables formatlarında da mevcut.41844 approved IPs, also available in TXT, JSON, CIDR, and iptables formats.

Tüm Formatları Gör View All Formats