Fortinet FortiGate integration

Fortinet FortiGate threat intelligence integration

Boost your Fortinet FortiGate firewall with Q-Feeds cyber threat intelligence (CTI). Use FortiGate External Connectors to pull real-time IP, URL and DNS threat feeds into your policies and block malicious traffic at the edge, with minimal effort and maximum impact.

  • 2,500+Intelligence sources
  • 20 minUpdate interval
  • 4 stepsTo full integration
  • 3Feed types: IP, URL, DNS
What it is

What is the Q-Feeds and FortiGate integration?

The Q-Feeds integration connects curated cyber threat intelligence directly to your Fortinet FortiGate firewall using native External Connectors (external threat feeds). FortiGate periodically fetches Q-Feeds blocklists of malicious IP addresses, domains and URLs over HTTPS and enforces them in your firewall, DNS and web filter policies.

The result is automated, always-current protection: known-bad indicators are blocked at the network edge before they reach your users or servers, with no manual list management. It runs alongside your existing FortiGuard subscriptions to add independent, multi-source intelligence.

Whether you run a single FortiGate or a large Security Fabric, the integration scales from a free proof of concept to full production use.

External Connectors

What you can block on FortiGate

Malicious IP feeds

Add an IP address threat feed to block inbound and outbound traffic to known-malicious hosts, botnets and command-and-control servers in your firewall policies.

Malicious URL feeds

Use a URL threat feed in the FortiGate web filter to stop access to phishing pages, malware downloads and other harmful links.

Malicious domain feeds

Feed malicious domains into the FortiGate DNS filter to block command-and-control and phishing domains at resolution time.

Curated categories

Choose focused feeds for phishing, botnets, malware, mobile and dark web threats, so you only enforce what is relevant to your organisation.

Benefits

Why add Q-Feeds to your FortiGate

  • Fewer false positives

    Indicators are cross-referenced across commercial, OSINT and governmental sources and curated to cut noise, so you block real threats, not legitimate traffic.

  • Refreshed every 20 minutes

    Feeds update every 20 minutes, so your FortiGate stays ahead of fast-moving campaigns automatically.

  • Multi-source resilience

    Combining many independent sources removes single-vendor blind spots and hardens your coverage.

  • Faster incident response

    Blocking at the edge means faster, more precise response and less time spent on internal investigations.

How it works

The Multi-Eyed Principle

The Multi-Eyed Principle emphasises using multiple sources of threat intelligence to strengthen the security and effectiveness of your existing firewall. By combining diverse feeds you achieve a more comprehensive, robust defence against cyber threats.

Multiple sources of IOCs

Commercial, OSINT and governmental intelligence combined in one firewall.

Simple 4-step implementation

Implementation is fast and easy with our 4-step manuals, and a proof of concept is completely free.

Setup

Integrate Q-Feeds with FortiGate in 4 steps

  1. Create your free account

    Sign up on the Q-Feeds Threat Intelligence Portal and copy your personal feed URLs for IP, URL and domain indicators.

  2. Add an External Connector

    In FortiOS, open Security Fabric, External Connectors and add a Threat Feed (IP address, domain name or URL) pointing to your Q-Feeds feed URL.

  3. Set the refresh interval

    Choose how often FortiGate pulls the feed and confirm the connector shows a healthy status with imported entries.

  4. Enforce in a policy

    Reference the external feed in a firewall policy, DNS filter or web filter to start blocking malicious traffic immediately.

Implementation

Implementation

Implementation is a breeze thanks to our native support for the Fortinet Next Generation Firewall. We've created convenient manuals for every use case, so your firewall can be hardened in no time.

View the manuals
Custom project

Your own Fortinet connector project?

Want to use Q-Feeds threat intelligence with Fortinet? Sign up for free and see the power of Q-Feeds for yourself.

Get started
FAQ

Frequently asked questions about the FortiGate integration

What is a FortiGate External Connector?

A FortiGate External Connector (external threat feed) lets FortiOS automatically download a list of malicious IPs, domains or URLs from an external source like Q-Feeds and use it in your security policies.

Which threat feeds can I add to FortiGate?

With Q-Feeds you can add IP address feeds, URL feeds and domain (DNS) feeds, and enforce them in firewall policies, the web filter and the DNS filter.

How often are the Q-Feeds threat feeds updated?

The feeds are refreshed every 20 minutes, so your FortiGate always enforces current intelligence without manual updates.

Do I need a specific FortiOS version?

External threat feeds are supported on current FortiGate firewalls running FortiOS. Our manuals cover the exact steps for your version.

Is there a free version?

Yes. The Q-Feeds Community edition is free and lets you test the FortiGate integration before upgrading to Plus or Premium for faster, premium intelligence.

Does it work alongside FortiGuard?

Yes. Q-Feeds adds independent, multi-source intelligence on top of your existing FortiGuard subscriptions for broader coverage.

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access