Best practice for thwarting port scanning?
I seem to get an awful lot of port scans to port 500, many/most on the same IP block.
I'm certain they're doing an overall scan of the network, but I've just implemented a notification alert on the following:
[ul]via Log & Report > Email Alert Settings (300E model) so I can keep tabs if any of my users are having problems (or are the target of a brute force attack).
..so I'm most aware of the port 500 hits. However, because these garbage notifications are bloating my inbox, I've overlooked legitimate login failures for my users, unintentionally.
What's the best approach to either stopping these scans from triggering an alert, or blocking the probes?
I'm fairly new to Fortinet products, so I'm not completely well-versed in the full capabilities of the firewall.
Possible approaches:
[ul]*I do have Intrusion Detection running, but I haven't yet setup a rule to target this behavior as I'm not entirely sure how the signatures and filters work.
Can anyone offer any suggestions?
