Fortinet FortiGate threat intelligence integration
Boost your Fortinet FortiGate firewall with Q-Feeds cyber threat intelligence (CTI). Use FortiGate External Connectors to pull real-time IP, URL and DNS threat feeds into your policies and block malicious traffic at the edge, with minimal effort and maximum impact.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 4 stepsTo full integration
- 3Feed types: IP, URL, DNS
What is the Q-Feeds and FortiGate integration?
The Q-Feeds integration connects curated cyber threat intelligence directly to your Fortinet FortiGate firewall using native External Connectors (external threat feeds). FortiGate periodically fetches Q-Feeds blocklists of malicious IP addresses, domains and URLs over HTTPS and enforces them in your firewall, DNS and web filter policies.
The result is automated, always-current protection: known-bad indicators are blocked at the network edge before they reach your users or servers, with no manual list management. It runs alongside your existing FortiGuard subscriptions to add independent, multi-source intelligence.
Whether you run a single FortiGate or a large Security Fabric, the integration scales from a free proof of concept to full production use.
What you can block on FortiGate
Malicious IP feeds
Add an IP address threat feed to block inbound and outbound traffic to known-malicious hosts, botnets and command-and-control servers in your firewall policies.
Malicious URL feeds
Use a URL threat feed in the FortiGate web filter to stop access to phishing pages, malware downloads and other harmful links.
Malicious domain feeds
Feed malicious domains into the FortiGate DNS filter to block command-and-control and phishing domains at resolution time.
Curated categories
Choose focused feeds for phishing, botnets, malware, mobile and dark web threats, so you only enforce what is relevant to your organisation.
Why add Q-Feeds to your FortiGate
-
Fewer false positives
Indicators are cross-referenced across commercial, OSINT and governmental sources and curated to cut noise, so you block real threats, not legitimate traffic.
-
Refreshed every 20 minutes
Feeds update every 20 minutes, so your FortiGate stays ahead of fast-moving campaigns automatically.
-
Multi-source resilience
Combining many independent sources removes single-vendor blind spots and hardens your coverage.
-
Faster incident response
Blocking at the edge means faster, more precise response and less time spent on internal investigations.
The Multi-Eyed Principle
The Multi-Eyed Principle emphasises using multiple sources of threat intelligence to strengthen the security and effectiveness of your existing firewall. By combining diverse feeds you achieve a more comprehensive, robust defence against cyber threats.
Multiple sources of IOCs
Commercial, OSINT and governmental intelligence combined in one firewall.
Simple 4-step implementation
Implementation is fast and easy with our 4-step manuals, and a proof of concept is completely free.
Integrate Q-Feeds with FortiGate in 4 steps
Create your free account
Sign up on the Q-Feeds Threat Intelligence Portal and copy your personal feed URLs for IP, URL and domain indicators.
Add an External Connector
In FortiOS, open Security Fabric, External Connectors and add a Threat Feed (IP address, domain name or URL) pointing to your Q-Feeds feed URL.
Set the refresh interval
Choose how often FortiGate pulls the feed and confirm the connector shows a healthy status with imported entries.
Enforce in a policy
Reference the external feed in a firewall policy, DNS filter or web filter to start blocking malicious traffic immediately.
Implementation
Implementation is a breeze thanks to our native support for the Fortinet Next Generation Firewall. We've created convenient manuals for every use case, so your firewall can be hardened in no time.
View the manualsYour own Fortinet connector project?
Want to use Q-Feeds threat intelligence with Fortinet? Sign up for free and see the power of Q-Feeds for yourself.
Get startedPrefer a different platform?
Frequently asked questions about the FortiGate integration
What is a FortiGate External Connector?
A FortiGate External Connector (external threat feed) lets FortiOS automatically download a list of malicious IPs, domains or URLs from an external source like Q-Feeds and use it in your security policies.
Which threat feeds can I add to FortiGate?
With Q-Feeds you can add IP address feeds, URL feeds and domain (DNS) feeds, and enforce them in firewall policies, the web filter and the DNS filter.
How often are the Q-Feeds threat feeds updated?
The feeds are refreshed every 20 minutes, so your FortiGate always enforces current intelligence without manual updates.
Do I need a specific FortiOS version?
External threat feeds are supported on current FortiGate firewalls running FortiOS. Our manuals cover the exact steps for your version.
Is there a free version?
Yes. The Q-Feeds Community edition is free and lets you test the FortiGate integration before upgrading to Plus or Premium for faster, premium intelligence.
Does it work alongside FortiGuard?
Yes. Q-Feeds adds independent, multi-source intelligence on top of your existing FortiGuard subscriptions for broader coverage.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access