SOP: Whitelisting an IP Address in FortiSIEM

Purpose

This SOP outlines the steps required to whitelist an IP address in FortiSIEM by editing an existing rule and adding an exception based on source or destination IP.

Prerequisites

- Access to FortiSIEM Supervisor with admin super account credentials.
- Knowledge of the rule for which the IP needs to be whitelisted.

Procedure

1.       Login to FortiSIEM Supervisor using your admin super account.

2.       Navigate to the 'Resources' section.

3.       Go to the 'Rules' tab.

4.       Search for the rule you want to modify to whitelist the IP address.

 

5.       Select the rule and click 'Edit'.

6.       Navigate to the 'Define Action' section.

7.       Go to the 'Exception' tab.



8.       Define the exception by specifying the Source IP or Destination IP to be whitelisted.

9.       Click 'Save' to apply the changes.


Notes

- Ensure that the IP address being whitelisted is verified and approved.
- Changes to rules may impact event handling and alerting; review thoroughly before saving.

No comments:

Post a Comment

Upgrade Cisco Catalyst 9200 and 9300 switches to IOS XE version 17.15.03

Prepare a pre-upgrade checklist for Catalyst 9200/9300 Here is a reliable pre-upgrade checklist for Cisco Catalyst 9200/9300 switches before...