Connectors
...
Configuration
Configuration at Turbine
3 min
setup fortigate asset with host & api details deploy component below execute block unblock domain remediation action withoutasset ssp note playbooks are created from v24 2 11, with fortigate connector v1 1 4 import all of the following configure playbook for blocking domain address open playbook “soc remediation actions“, go to the flow of record actions “block observables”, under the if condition of domain, change component to “execute block/unblock domain remediation action“ go to component “execute block/unblock domain remediation action“, set fortigate’s network address name at the subplaybook input , according to the predefined network address group’s name provided by the firewall team configure playbook for un blocking domain address open playbook “soc remediation actions“, go to the flow of record actions “unblock observables”, under the if condition of domain, change component to “execute block/unblock domain remediation action“ go to component “execute block/unblock domain remediation action“, set fortigate’s network address name at the subplaybook input , according to the predefined network address group’s name provided by the firewall team fortigate actions in component “execute fortigate add address to network address group“ and “execute fortigate remove address from network address group“ are configured to run against $remote pool change it to $default if the turbine instance that you are working on has direct access to fortigate, without remote agent that shall be it, and you are good to test out and validate the result at fortigate