Quantcast
Channel: Fortinet GURU
Viewing all articles
Browse latest Browse all 2380

Subnet lists – FortiAnalyzer – FortiOS 6.2.3

$
0
0

Subnet lists

In Incidents & Events, you can define subnet lists which can be added to subnet groups.

Subnet lists and groups can be used to create a whitelist or blacklist in event handlers.

Creating a subnet list

To create a new subnet:

  1. Go to Incidents & Events > Subnet Lists.
  2. Select Create New > Subnet.
  3. Enter a name for the subnet.
  4. Select a Subnet type and configure the corresponding information. Subnet types include: l Subnet Notation l IP Range l Batch Add
  5. Select OK.

Once a subnet has been created, it can be edited, cloned, or deleted by highlighting it and selecting the corresponding action in Subnet List toolbar.

Creating a subnet group

To create a subnet group:

  1. Go to Incidents & Events > Subnet List.
  2. Select Create New > Subnet Group.
  3. Enter a name for the subnet group.
  4. Select the subnet entries to be included in the group and select OK in the pop-up window.
  5. Select OK.

Once a subnet group has been created, it can be edited, cloned, or deleted by highlighting it and selecting the corresponding action in Subnet List toolbar.

Assigning subnet filters to event handlers

You can streamline SOC processes by defining a subnet whitelist/blacklist for event handlers. These addresses can be linked to any event handler to enable or prevent it from triggering an event. Creating a subnet whitelist/blacklist for event handlers eliminates the need to specify common networks in every event handler.

To include or exclude subnets in an event handler:

  1. Go to Incidents & Events > Event HandlerList.
  2. Select an event handler to edit from the list.
  3. In the Subnet category, select Specify.
  4. Choose which subnets to include or exclude by selecting them from the corresponding dropdown menu.
  5. Select OK.

Viewing all articles
Browse latest Browse all 2380

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>