PrecisionSec publishes a domain-only version of the free ClickFix feed specifically for FortiGate: one domain per line, with no other columns, so it can be pulled straight into a FortiGate External Connector. It’s built from the same lure, distribution and C2 domains as the standard CSV feed, just reformatted for what FortiGate’s threat feed connectors expect. This guide is based on the Fortinet documentation; adjust the steps for your specific FortiGate model and firmware version.

Credentials required. If you have not yet received your free ClickFix feed credentials, sign up here.

Choose a retention window

The feed is published at four retention windows. Each one lists every ClickFix domain detected within that time period, one per line:

Window Feed URL
1 day https://trial.precisionsec.com/clickfix/clickfix_domains_fortinet_1day.txt
7 days https://trial.precisionsec.com/clickfix/clickfix_domains_fortinet_7day.txt
30 days https://trial.precisionsec.com/clickfix/clickfix_domains_fortinet_30day.txt
60 days https://trial.precisionsec.com/clickfix/clickfix_domains_fortinet_60day.txt

We recommend starting with 60day. ClickFix lure domains get reused across campaigns, so the widest window gives you the most blocking coverage. The tradeoff is that some domains that far back may have been reclaimed or gone dormant; if you’d rather keep the list tighter and fresher, use 7day or 30day instead. A .csv copy with identical contents exists at each of the same paths (.csv instead of .txt) — point FortiGate at the .txt version.

Add the External Connector

  1. Log into the FortiGate Web Interface

    • Open your web browser and enter the IP address of your FortiGate firewall admin interface. Log in using your administrator credentials.
  2. Go to the ‘Security Fabric’ Section

    • On the left-hand sidebar, click on Security Fabric. In the sub-menu that opens, click on External Connectors and then click Create New.
  3. Create a New External Blocklist

    • Scroll to the bottom of the ‘New External Connector’ page to the Threat Feeds section and select Domain Name. Selecting IP Address instead will produce a connector that silently loads zero entries, since this feed contains only domains.
  4. Enter the Feed Details

    • Name: Give the blocklist a unique name, such as “PrecisionSec ClickFix Domains”
    • Use the default Update method of External Feed
    • URI of External Resource: the URL for your chosen retention window from the table above
    • Toggle the HTTP Basic Auth switch to On
    • Enter the username and password you were provided
    • Refresh Rate: PrecisionSec recommends setting this to 60 minutes
    • Click OK and ensure the toggle on the new card is enabled
  5. Confirm the feed loaded

    • Hover over the new card and click View Entries to confirm domains are populated. An empty list here almost always means IP Address was selected in step 3 instead of Domain Name.

Apply the feed so it actually blocks traffic

Creating the External Connector only defines the feed as an object. FortiGate won’t act on it until a security profile references it:

  • Security Profiles → DNS Filter, edit the profile applied to your users, and set the PrecisionSec ClickFix category’s action to Block. DNS filtering works without SSL inspection configured.
  • Alternatively, reference the same feed from a Web Filter profile. Web filtering requires SSL inspection to act on HTTPS traffic.
  • Apply the updated profile to the firewall policy that carries your outbound user traffic. Without this step, the connector loads domains but nothing is blocked.

Troubleshooting

  • 401 / authentication error fetching the feed — the HTTP Basic Auth username or password is missing or incorrect. Re-check the credentials from your sign-up email.
  • Connector shows zero entries — confirm you selected Domain Name as the threat feed type, not IP Address.
  • Lines starting with # at the top of the file — these are comment headers (feed name and last-updated timestamp). FortiGate ignores them; they aren’t a parsing error.

More resources

Ready to see all of our data?

Request a 15-day free trial and get live, curated threat intelligence feeds.

Request a 15-day trial