Skip to main content
lostboy10
Explorer II
January 17, 2025
Question

Allowing PT Scan for URLs in Fortinet

  • January 17, 2025
  • 1 reply
  • 502 views

i have a set of public urls which are required to be VA/PT scanned by an external agency.. the problem is when the traffic gets initiated from the PT server i can see traffic getting blocked in fortigate via an IPS profile mapped in the access policy..i then added the IP of PT server in exemption list post which there were no IPS deny logs ..however, there are logs with 'blank" action and a message of server-rst... there is no issue with application at the same time as it is working fine as checked from a diff system.. i am suspecting a setting in fortigate which is seeing this as an attack but cant figure out what it is..

 

anyone faced a similar issue ? any help is appreciated.

 

thanks

1 reply

AEK
SuperUser
SuperUser
January 17, 2025

Server-rst (reset TCP connection from server side) is an action performed by the server, not by FortiGate. The FortiGate only reports the action in the logs.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!