IP blocking NGFW logrhythm

ashark47 Lv1Posted Feb-18-2026 23:40

Is it possible to enable automatic IP address blocking on the Sangfor firewall through logrhythm

Humayun Ahmed has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Yes.  Attack detected in LogRhythm

Alarm rule triggered

SmartResponse plugin executes script/API call

Script sends IP to Sangfor firewall

Firewall adds IP to blacklist / block policy
Is this answer helpful?
Muhammad Abid Lv2Posted Feb-21-2026 15:15
  
Yes — it is possible, but not natively out-of-the-box.

LogRhythm can detect malicious IPs through correlation rules and then trigger an automated response (script or API call). If your Sangfor firewall supports API or remote CLI access, LogRhythm can push the detected IP into the firewall’s blacklist/block policy automatically.

I Can Help:

Change

Moderator on This Board

1
148
3

Started Topics

Followers

Follow

954
194
98

Started Topics

Followers

Follow

Board Leaders