頁面目錄
前言:
FortiGate Automation 功能可實現自動化程序,可依據發生的資安事件/自身狀況/排程執行各種自動化程序強化事件通報處理,以下由我來展示一些範例。
data:image/s3,"s3://crabby-images/6ebca/6ebca08097278cd2de82547af22fc1df927a84f2" alt="FortiGate Automation"
環境說明:
FortiOS版本:After 7.0
FortiGate Automation 設定:
Automation 範例:
data:image/s3,"s3://crabby-images/999e9/999e961a58e30f495ce1e3751f1e95d157dca7e8" alt="FortiGate Automation"
data:image/s3,"s3://crabby-images/018f7/018f72f7f109dfd1f8a837e250dedf790facf253" alt="FortiGate Automation"
data:image/s3,"s3://crabby-images/70219/70219132049313a1f1a57127b42072b3e4b8cb14" alt="FortiGate Automation"
Automation範例:
1.自動排程備份設定
data:image/s3,"s3://crabby-images/4a670/4a670e83f8ac8652a091822bd528c28b6c70acf9" alt="FortiGate Automation"
data:image/s3,"s3://crabby-images/a27b4/a27b4873205232a6d0d30f9ba1b2407d05b42142" alt=""
execute backup config ftp /Backup/backup-%%date%%.conf 172.16.4.221 testuser testpassword
execute backup config ftp <FTP路徑與設定檔名稱-使用變數加上日期> <FTP IP> <帳號> <密碼>
data:image/s3,"s3://crabby-images/d8075/d807523552d3aa8549fcf8fea3f64cb1d2b842f9" alt=""
2.設定異動告警
data:image/s3,"s3://crabby-images/2f67b/2f67b5f9d147b0d864ab13a645f0b1b36a1a80ba" alt=""
data:image/s3,"s3://crabby-images/77c79/77c79f3ac2ae7818c73cae9d422e73a2dfcca880" alt=""
data:image/s3,"s3://crabby-images/8133a/8133a3f1425f8eb66dddd4c4436dcbb6b72af180" alt=""
3.IPS事件自動ban ip
data:image/s3,"s3://crabby-images/1fd69/1fd694ee9e83693469d1ecc86e6e7bc64b78c6ff" alt=""
data:image/s3,"s3://crabby-images/d51b0/d51b096547ff84b69acd4ff1cd747990d488957f" alt=""
diagnose user banned-ip add src4 %%log.srcip%% indefinite admin
紅字標示是內建參數可抓取Event log內的來源IP參數
設定indefinite永久Ban IP
data:image/s3,"s3://crabby-images/ae71a/ae71a2de9f494a9534fe349878b5ce0a5d5d77d5" alt=""
4.SSL-VPN封鎖登入失敗IP
data:image/s3,"s3://crabby-images/48a9a/48a9aed98319b7626e5e276bc8093aba7fdd8b4f" alt=""
config firewall address
edit %%log.remip%%
set subnet %%log.remip%% 255.255.255.255
next
end
config firewall addrgrp
edit high risk country
append member %%log.remip%%
end
紅字標示是內建參數可抓取Event log內的來源IP參數
藍字標示的是預先設定好的位址物件已套用至Local policy中
data:image/s3,"s3://crabby-images/eb965/eb9653da303ed17cdd3afde0476e5620a5a079d8" alt=""