Before you start, create your API key and feed URLs in the portal. See Get your threat feeds. Schedule refreshes at least every 20 minutes. Shorter intervals do not improve coverage and may overload the API.
Available indicator lists
Q-Feeds provides regularly updated IoC lists you can import into FortiGate:
- Malware IPs (
feed_type=malware_ip): dangerous IP addresses - Malware domains (
feed_type=malware_domains): malicious domains - Malicious URLs (
feed_type=malicious_urls): malicious URLs
Example feed URL shape:
https://api.qfeeds.com/api?feed_type=malware_ip&api_token=YOUR_TOKEN&limit=130000
You can verify a feed with HTTP Basic auth (username api_token, password = your API key):
curl -v -u api_token:YOUR_TOKEN "https://api.qfeeds.com/api?feed_type=malware_ip&limit=130000"
Add an External Connector
From FortiOS 6.0, FortiGate can pull IoCs from HTTP/HTTPS text files. After import you can use them in Web Filtering, DNS Filtering, antivirus profiles, and as source or destination in IPv4 and proxy policies.
- Go to Security Fabric > External Connectors and select Create New.
- Choose the connector type that matches the feed:
- IP Address for the malware IP feed
- Domain Name for the malware domain feed
- FortiGuard Category for the malicious URL feed
- Set Name to something clear, for example
Q-Feeds Malicious IPs. - In URI of External Resource, paste your feed URL from the portal.
- Add
&limit=130000to the URL. FortiGate allows about 10 MB or 131,072 IoCs per dynamic list; without a limit the full feed may exceed appliance capacity. - Enable HTTP Basic authentication. Username is
api_token; password is your Q-Feeds API key. If Basic auth fails on your firmware, append&api_token=YOUR_TOKENto the URL instead. - Set Refresh Rate to match your license update interval (20 minutes for Premium; longer for Plus / Community).
- Optionally add comments, switch Status on, and select OK.
The FortiGuard Category connector is the only external feed type that holds URLs, one per line, and it asks more of the firewall than the IP and domain feeds do. The malicious URL feed needs a Q-Feeds Premium licence. On the FortiGate the imported feed shows up as a category under Remote Categories in a Web Filter profile, using it there in NGFW profile or policy mode needs a FortiGuard licence, and matching a full URL path needs SSL inspection in the profile. Without inspection the firewall only sees the hostname.
Verify the feed downloaded
Select the connector and choose View content to confirm indicators were downloaded. FortiGate automatically splits IP feeds into separate IPv4 and IPv6 lists.
Use the lists in policies
Once imported, apply each connector where it belongs: the IP feed as source or destination in IPv4 and proxy policies or in firewall rules, the domain feed in a DNS Filter profile, and the malicious URL feed as a remote category in a Web Filter profile. Repeat the connector setup for each feed type you need.