Fortinet white logo
Fortinet white logo

CLI reference

config system fortiguard ioc

config system fortiguard ioc

Use this command to configure FortiNDR to query IOC (Indicator of Compromise) data from a custom FortiGuard server instead of the default.

Syntax

config system fortiguard ioc
	set ioc-override-server-address <ovr_svr>
	set ioc-override-server-port <port_num>
	set ioc-override-server-status <enable/disable>
end

Variable

Description

Default

ioc-override-server-address

Specifies the override IP address of the FortiGuard IOC server. The default is 0.0.0.0

  • This setting only accepts a single IPv4/IPv6 address.
  • Hostnames are not supported.
  • Multiple addresses are not allowed—only one override server can be configured at a time.
  • If the configured address is unreachable, IOC queries may fail.

0.0.0.0

ioc-override-server-port

Port number to ioc override fortiguard server. The default is 443

44

ioc-override-server-status

{enable | disable}

When enabled, FortiNDR will send IOC queries to the override server specified in ioc-override-server-address.

disable

config system fortiguard ioc

config system fortiguard ioc

Use this command to configure FortiNDR to query IOC (Indicator of Compromise) data from a custom FortiGuard server instead of the default.

Syntax

config system fortiguard ioc
	set ioc-override-server-address <ovr_svr>
	set ioc-override-server-port <port_num>
	set ioc-override-server-status <enable/disable>
end

Variable

Description

Default

ioc-override-server-address

Specifies the override IP address of the FortiGuard IOC server. The default is 0.0.0.0

  • This setting only accepts a single IPv4/IPv6 address.
  • Hostnames are not supported.
  • Multiple addresses are not allowed—only one override server can be configured at a time.
  • If the configured address is unreachable, IOC queries may fail.

0.0.0.0

ioc-override-server-port

Port number to ioc override fortiguard server. The default is 443

44

ioc-override-server-status

{enable | disable}

When enabled, FortiNDR will send IOC queries to the override server specified in ioc-override-server-address.

disable