IP blocking NGFW logrhythm

ashark47 Lv1Posted Feb-18-2026 23:40

Is it possible to enable automatic IP address blocking on the Sangfor firewall through logrhythm

By solving this question, you may help 961 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Muhammad Abid Lv2Posted Feb-21-2026 15:15
  
Yes — it is possible, but not natively out-of-the-box.

LogRhythm can detect malicious IPs through correlation rules and then trigger an automated response (script or API call). If your Sangfor firewall supports API or remote CLI access, LogRhythm can push the detected IP into the firewall’s blacklist/block policy automatically.

Humayun Ahmed Lv3Posted Feb-20-2026 11:38
  
Yes.  Attack detected in LogRhythm

Alarm rule triggered

SmartResponse plugin executes script/API call

Script sends IP to Sangfor firewall

Firewall adds IP to blacklist / block policy

I Can Help:

Change

Moderator on This Board

1
148
3

Started Topics

Followers

Follow

917
183
94

Started Topics

Followers

Follow

Board Leaders