Forum Discussion

Usama_Saleem's avatar
Usama_Saleem
Brass Contributor
Sep 25, 2023

IP Block on on-premises Firewall using Sentinel Playbooks

Hello- I was wondering if we can block IP address on on-prem firewall that has no internet connectivity. Can we achieve this using Sentinel playbook? I don't want my on-prem firewall to be exposed.

  • Are looking to manage a list of IPs that are blocked by your OnPremises Firewall in Sentinel or do you want a Remediation Action to write IPs that you find to be Suspicios through Hunting on demand?
    Either way, if you do not want to expose your Firewall to the internet your firewall vendor will either have to support REST API Calls originating from the Firewall or you need an API that is Accessible from OnPremises and a Hybrid Worker - Here is an Article by John Joyner about what I think you want to achieve - https://blog.johnjoyner.net/azure-sentinel-soar-worker-azure-arc-azure-automation/

Resources