Splunk SOAR

How to block incoming traffic (source ip at FW policy) with phantom check point/ fortinet apps?

stevenaung
New Member

Hi all,

I was testing out phanom to contain malicious IPs with my perimeter FWs.
The problem is that it only block as destination IP at FW and i didn't see any parameter to define whether I want to block as destination or source or both.
I believe FW API supports this functionality but somehow it is missing.
Any thoughts on this?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...