Splunk SOAR

How to block incoming traffic (source ip at FW policy) with phantom check point/ fortinet apps?

stevenaung
New Member

Hi all,

I was testing out phanom to contain malicious IPs with my perimeter FWs.
The problem is that it only block as destination IP at FW and i didn't see any parameter to define whether I want to block as destination or source or both.
I believe FW API supports this functionality but somehow it is missing.
Any thoughts on this?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...