Skip to main content
MikeJ
New Member
January 28, 2016
Question

Detect/Dropped vs Passthrough

  • January 28, 2016
  • 2 replies
  • 8020 views

This might be a n00b question, but I just want to make sure I understand Fortigate processes traffic and alerts.

 

In the Fortianalyzer/Fortiview/Logs:

 

So, when I research an alert for Angler EK and I check the IPS logs, I see "detected" and usually "dropped" for a given IP, but when I search for the IP in the Web Filters and the "action" says "passthrough".

 

My question is, did the Fortigate allow the website requests from the IP and then when it detects Angler, the IPS then blocks the traffic? Or am I missing something?

 

I just want to know that if I see alerts on a particular EK like Angler or Nuclear and I check and see detected and dropped that there is no more action I need to take, like remediation, etc...

 

Thanks all,

 

MikeJ

 

 

 

    2 replies

    razor
    Visitor III
    February 8, 2016

    Hi MikeJ,

     

    You should capture the packets and follow the connection stream.

     

    The capture will show you which system blocks the connection first, and which systems follows. You could reproduce this using an isolated virtual machine. You could also use the diagnose debug command to capture the packets.

    emnoc
    New Member
    February 8, 2016

    I  posted  this earlier, but the  life of  the packet should be studied by all so you know what and how a packet flow across a  Fortigate & in what order.

     

    http://docs.fortinet.com/uploaded/files/2674/fortios-life-of-a-packet-524.pdf

     

    Be aware of the packet flow  ( in and out ) and the logs for what you are seeing. As far as packet capture, you could have also enable it on the IPS sensor. if the signature has a block  vrs a a pass, than you can assure it was blocked.

     

    Make sure the sign is status enable also.

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.