THE SAFEHOUSE / JOURNAL

🚀 Supercharge Your FortiGate: Proactive Defence with Q-Feeds Threat Intelligence 🚀

23 November 2025· 4 min read

Use 14 Days Free API Access Tools

In today’s cybersecurity landscape, merely reacting to threats isn’t enough. You need to be proactive. Your Next-Generation Firewall (NGFW), like a FortiGate, is your network’s frontline and its effectiveness hinges on having the most current information about what’s dangerous out there.

This is where integrating external dynamic lists or Threat Feeds comes in. By connecting FortiGate to dynamic lists of known Indicators of Compromise (IoCs) like malicious IPs and domains, you can automatically block threats before they even have a chance to enter your network.

What is a Threat Feed and Why is it Essential?

A Threat Feed is a constantly updated source of threat intelligence. It provides lists of IoCs data points that indicate a potential security breach or threat which includes known malicious IP addresses, dangerous domains and URLs.

Manually updating blacklists of millions of threats is impossible. A good threat feed automates this process, ensuring your firewall always has the latest intelligence to defend against emerging threats.

Q-Feeds is one such provider offering dynamic, up-to-date lists of IoCs designed to integrate seamlessly with security controls like your FortiGate firewall.

Visit on Qfeeds Website and request for free access

🛠️ Integrating Q-Feeds into Your FortiGate️ ️️🛠️

The FortiGate’s Security Fabric External Connectors feature allows you to subscribe to these dynamic threat feeds via a URL. This is the mechanism that keeps your firewall automatically updated.

Firstly You need to register with official email id on Qfeeds then need to login in TIP of Qfeeds. This step will help you to generate API as follows:-

Register for Free Trial as TIP with your official Email ID Create API key as Required

Here are the specific connector URLs you’ll use for Q-Feeds’ domain/URL and IP address intelligence:

Threat Intelligence Type Q-Feeds Connector URL (Example)

Malware Domain/URL List

https://api.qfeeds.com/api?feed_type=malware_domains&api_token=YOUR_TOKEN&limit=130000

Malware IP Address List

https://api.qfeeds.com/api?feed_type=malware_ip&api_token=YOUR_TOKEN&limit=130000

Note:

  1. Remember to replace YOUR_TOKEN with your actual Q-Feeds API token.
  2. The limit=130000 parameter specifies the maximum number of entries the FortiGate should pull from the feed.

Step-by-Step FortiGate Configuration:

  1. Navigate to External Connectors: In your FortiGate GUI, go to Security Fabric > External Connectors.
  2. Create New Connector: Click Create New.
  3. Choose Feed Type:

4. Enter Details:

5. Repeat the process for the second feed type.

Feature Usage

🛡️ Applying the Threat Feeds to Your Policies 🛡️

Once imported, the lists become available as dynamic address objects that can be used in your FortiGate security policies.

The power is in the application. You can integrate the Q-Feed lists into various policy types, including Firewall rules, Web Filtering, DNS Filtering and Antivirus Profiles.

1. Blocking Malicious IP Traffic (Firewall Policy)

You can create a dedicated Deny policy to immediately block traffic destined for or originating from a known malicious IP address:

2. Blocking Malicious Domains (DNS/Web Filter)

For domain and URL lists, you’ll typically integrate them into a DNS Filter or Web Filter profile:

Image

You can also verify the Q-Feed logs as follows:-

Able to see logs of Feed only

Conclusion

By leveraging dynamic, external threat intelligence from providers like Q-Feeds and integrating it via FortiGate’s External Connectors, you transition your defence from a static checkpoint to a dynamic, living shield. This simple configuration dramatically improves your network’s protection against new and emerging threats, allowing your firewall to automatically block harmful traffic and stay ahead of the curve.

Don’t wait for the next attack to learn about the threat preempt it with real-time intelligence!

Related reading