Configuring blocklisted IPv4 addresses
Use Blocklisted IPv4 Address option to deny ACL large sets of blocklisted IPv4 addresses.
Note:
-
Blocklisted IPv4 addresses are always blocked, no matter the individual SPP Detection/Prevention Mode setting.
-
FortiDDoS does not support large IPv6 blockslists. Use SPP (preferred) or Global ACLs instead.
To configure:
- Go to Global Protection > Blocklist > Blocklisted IPv4.
- Select the option based on the requirement:
- Upload: Choose and upload the file with the list of blocklisted addresses. The supported file formats are Text, MS-DOS, CSV MS-DOS and CSV (comma delimited).
Note:
- List entries must be individual IP address with no netmask of any type. Order is not important.
- If you upload a new file, the new file replaces the older database but does not affect the individually added address from Create New below. There is no “append” function for uploaded files.
- FortiDDoS supports a maximum of 1 million IPv4 addresses in the upload file.
- Uploads can take several minutes and there is no progress meter. Failure and success messages are displayed as appropriate.
- Download: Save the blocklisted address list to your system. This file includes uploaded and individually added addresses.
- Clear: Clear the current address list AND any individually added addresses from the GUI page list.
- Create New: Add a new single address and click Save to include in the existing list. Added individual addresses are listed on the Blocklist page. FortiDDoS supports a maximum of 1024 manually added IP Addresses.
- Delete: Delete added individual selected addresses from the list on the Blocklist page.
- Upload: Choose and upload the file with the list of blocklisted addresses. The supported file formats are Text, MS-DOS, CSV MS-DOS and CSV (comma delimited).