Skip to main content
MegaSistemas
New Member
August 14, 2018
Solved

automatic intrusion ip block

  • August 14, 2018
  • 2 replies
  • 15708 views

Hello guys

 

I noticed that a certain ip tried to invade a web server and IPS dropped that attempt, but soon after that same ip tried several more times. Is there a way to configure FGT to automatically block this ip for minutes or hours, so you can not keep trying every second? or that it is inserted into a blacklist?

    Best answer by darwin_FTNT

    See the following and enable IPS utm profile quarantine feature:

     

    https://forum.fortinet.com/tm.aspx?m=151871

     

    Quarantine list is maintained by kernel and is more efficient in cpu usage in terms of blocking quarantined client connections.

     

    2 replies

    darwin_FTNT
    Staff
    Staff
    August 15, 2018

    See the following and enable IPS utm profile quarantine feature:

     

    https://forum.fortinet.com/tm.aspx?m=151871

     

    Quarantine list is maintained by kernel and is more efficient in cpu usage in terms of blocking quarantined client connections.

     

    Bruno_Pereira
    New Member
    August 15, 2018

    Hello,

     

    it's possibilite with quarantine, you can set the time.You can then check the blocked IPs on monitor> quarantine monitor.

     

     

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!