
In today’s cybersecurity landscape, merely reacting to threats isn’t enough. You need to be proactive. Your Next-Generation Firewall (NGFW), like a FortiGate, is your network’s frontline and its effectiveness hinges on having the most current information about what’s dangerous out there.
This is where integrating external dynamic lists or Threat Feeds comes in. By connecting FortiGate to dynamic lists of known Indicators of Compromise (IoCs) like malicious IPs and domains, you can automatically block threats before they even have a chance to enter your network.
What is a Threat Feed and Why is it Essential?
A Threat Feed is a constantly updated source of threat intelligence. It provides lists of IoCs data points that indicate a potential security breach or threat which includes known malicious IP addresses, dangerous domains and URLs.
Manually updating blacklists of millions of threats is impossible. A good threat feed automates this process, ensuring your firewall always has the latest intelligence to defend against emerging threats.
Q-Feeds is one such provider offering dynamic, up-to-date lists of IoCs designed to integrate seamlessly with security controls like your FortiGate firewall.

🛠️ Integrating Q-Feeds into Your FortiGate️ ️️🛠️
The FortiGate’s Security Fabric External Connectors feature allows you to subscribe to these dynamic threat feeds via a URL. This is the mechanism that keeps your firewall automatically updated.
Firstly You need to register with official email id on Qfeeds then need to login in TIP of Qfeeds. This step will help you to generate API as follows:-

Here are the specific connector URLs you’ll use for Q-Feeds’ domain/URL and IP address intelligence:
Threat Intelligence Type Q-Feeds Connector URL (Example)
Malware Domain/URL List
https://api.qfeeds.com/api?feed_type=malware_domains&api_token=YOUR_TOKEN&limit=130000
Malware IP Address List
https://api.qfeeds.com/api?feed_type=malware_ip&api_token=YOUR_TOKEN&limit=130000
Note:
- Remember to replace
YOUR_TOKENwith your actual Q-Feeds API token. - The
limit=130000parameter specifies the maximum number of entries the FortiGate should pull from the feed.
Step-by-Step FortiGate Configuration:
- Navigate to External Connectors: In your FortiGate GUI, go to Security Fabric > External Connectors.
- Create New Connector: Click Create New.
- Choose Feed Type:
- For the Malware IP Address List, select IP Address.
- For the Malware Domain/URL List, you will typically select Domain Name or FortiGuard Category (which handles URLs) depending on the desired application.
4. Enter Details:
- Give the connector a meaningful Name (e.g.,
Q-Feed-Malware-IPs). - Set the Update Method to External Feed.
- Paste the corresponding Q-Feeds URL into the URL field.
- Configure the Refresh Rate (e.g., set to 5 minutes, though the maximum interval is 43200 minutes or 30 days depending on model/firmware) to ensure rapid updates.
5. Repeat the process for the second feed type.

🛡️ Applying the Threat Feeds to Your Policies 🛡️
Once imported, the lists become available as dynamic address objects that can be used in your FortiGate security policies.
The power is in the application. You can integrate the Q-Feed lists into various policy types, including Firewall rules, Web Filtering, DNS Filtering and Antivirus Profiles.
1. Blocking Malicious IP Traffic (Firewall Policy)
You can create a dedicated Deny policy to immediately block traffic destined for or originating from a known malicious IP address:
- Go to Policy & Objects > IPv4 Policy.
- Create a New Policy.
- Set the Action to DENY.
- In the Destination field, add the Q-Feed IP List you created. * This instantly blocks any traffic attempting to reach an IP address on that list, regardless of the service or port.
2. Blocking Malicious Domains (DNS/Web Filter)
For domain and URL lists, you’ll typically integrate them into a DNS Filter or Web Filter profile:
- Apply the Q-Feed Domain List to your DNS Filter profile to block DNS resolution for those domains.
- Apply the Q-Feed URL List to your Web Filter profile to block HTTP/HTTPS access to those known malicious sites.

You can also verify the Q-Feed logs as follows:-

Conclusion
By leveraging dynamic, external threat intelligence from providers like Q-Feeds and integrating it via FortiGate’s External Connectors, you transition your defence from a static checkpoint to a dynamic, living shield. This simple configuration dramatically improves your network’s protection against new and emerging threats, allowing your firewall to automatically block harmful traffic and stay ahead of the curve.
Don’t wait for the next attack to learn about the threat preempt it with real-time intelligence!