A standard FortiGate address group can hold up to 600 members. Most organisations will never come close to that limit, but for one financial services client operating an active managed-security environment, 600 was no longer enough.
The client’s SOC generates threat intelligence. When its monitoring identifies patterns of malicious traffic attempting to reach its systems, the team compiles a list of IP addresses to block and passes it to us. We manage the firewall, so the action lands on our desk.
For a while, the process was straightforward. We added the IP addresses to the relevant FortiGate address group, applied the necessary inbound and outbound block rules, and cleared any existing sessions associated with those addresses. Clean, simple, done.
Then the lists started growing.
Within a week or two, the 600-member address group was full and we created a second group, then a third. Each new group introduced more configuration work. Every policy that referenced the first group had to be updated to include the second and then the third. The maintenance overhead increased steadily, and so did the risk of a policy being missed or applied inconsistently.
The problem was no longer simply the number of malicious IP addresses. The architecture itself needed to change!
The Better Architecture for Threat Intelligence Integration
FortiGate firewalls support a native external threat-feed mechanism that works differently from a conventional address group. Instead of storing every address as an individual object inside the firewall configuration, the FortiGate periodically retrieves a formatted list from an external endpoint. When that list is updated, the firewall retrieves the changes automatically.
The capacity increases dramatically. Depending on the FortiGate model and FortiOS version, an external threat feed can support hundreds of thousands of entries which is far beyond the 600-member limit of a standard address group. The policies also remain cleaner because only one feed needs to be referenced, regardless of how many addresses it contains.
Building the solution meant creating the application and data store behind that endpoint. We developed a simple web application that holds the IP list, accepts updates through a controlled interface and publishes the formatted feed that the FortiGate retrieves on schedule.
When a new list of malicious IP addresses arrives from the clients SOC, our engineers add the entries to the application. The FortiGate then retrieves the updated feed during its next scheduled poll.
One Threat Feed, Multiple Sources of Intelligence
During development, another opportunity became apparent. A separate client’s connectivity reporting regularly surfaces IP addresses that appear suspicious, generate false positives or require policy review. These addresses may not justify an immediate permanent block, but they still need to be assessed. The same architecture can support intelligence from multiple approved sources, not only a single SOC relationship. This creates the potential for the threat feed to evolve into a broader intelligence layer across the client base.
An IP address identified in one environment could be evaluated by our security team and, where the intelligence is sufficiently reliable and relevant, incorporated into protection for other participating clients. That does not mean that every suspicious address should automatically be blocked everywhere.
IP addresses can be shared, reassigned or associated with legitimate cloud and hosting services. Wider use of threat intelligence therefore requires validation, allow-list checks, expiry rules and client-specific policy decisions. The value lies not in creating one indiscriminate global blacklist, but in creating a controlled system through which intelligence can be assessed once and applied appropriately where it adds value.
What a Smarter Firewall Management Approach Looks Like in Practice
When we told the client’s InfoSec team that we were moving from multiple address groups to a dynamic external threat feed, the response was immediate: “I love you.” It was not a formal sign-off. It was an engineer recognising that someone had solved a problem the team had been quietly living with.
That reaction says something about how managed-firewall services are often delivered.
The standard approach would have been to continue creating overflow groups, replicating policies and allowing the client’s security team to absorb the increasing friction.
The better approach was to step back and ask whether the underlying process could be redesigned to work more safely and efficiently at scale.
The application is now used daily by our engineering team. New SOC requests are added directly to the feed, and the FortiGate retrieves the updated list automatically.
The system has also been documented so that any authorised engineer can manage it without needing to understand the underlying build.
What This Means for Managed Security Operations
Managed-firewall services are often described in terms of uptime, response times and policy management. Those things matter. But the value of having an embedded security team managing your firewall is not only that someone will act quickly when a block list arrives. It is that someone will examine how that block list is being processed and build a better system when the existing approach starts to break.
That is the difference between a provider who executes instructions and a partner who manages your security infrastructure with the same care they would apply to their own.
If your organisation relies on active threat intelligence — whether from an internal SOC, a third-party feed, or your own network monitoring — the infrastructure handling that intelligence deserves the same scrutiny as the threats themselves. Our Trusted Response Centre is built around exactly this kind of proactive, engineering-led approach to managed security: not just acting on intelligence, but building the systems that make intelligence actionable at scale.
If you would like to discuss how proactive threat management could work for your environment, we would be happy to talk through your current approach.
