Skip to main content
defsdefs12
Explorer II
July 29, 2026
Question

DOS Policy threshold behavior

  • July 29, 2026
  • 3 replies
  • 92 views

Hi Fortinet Team, 

 

Good day! We’d like to confirm behavior of DOS policy on fortigate, we have initially created a policy from internal network to public with set the UDP_Flood as blocked, initially set the threshold to 5000 and is reached. what are the expected experienced

    3 replies

    fabs-net
    Explorer III
    July 29, 2026

    Hi, the usual behavoir is that packets exceeding the threshold are dropped immediately and a log entry should be generated.

    Maybe keep in mind that if your company is using MS Teams, there could be problems when UDP flood DOS is in place, see this:
     



    Greetings

    Every packet has a journey.
    Yurisk
    SuperUser
    SuperUser
    July 29, 2026

    “From internal to public” ? Do you mean you protect Internet from hosts in LAN DOSing the hosts on the Internet? If so, it would be the 1st such usage in history of Fortigates. If you mean from Internet to the Fortigate, then be aware that all the thresholds in DDOS policy are absolute, Layer 4 based and has no understanding of the applications used. This means, for example,  if you open multiple video/audio streaming apps - Zoom/Teams and such, and they all use UDP, Fortigate will block such legit traffic if it reaches the pre-defined value.   

     

    So if you are 100% sure you want to use this feature, first monitor your daily traffic patterns and usage to know what the regular UDP/TCP packets rate and set DDOS thresholds accordingly. There is no “best practices” here as each network has its own unique traffic patterns. My own best practice with DDoS policy on FOrtigate is never to use it. 

    yurisk.info - all things Fortinet blog, no ads
    GauravPandya
    Explorer
    July 29, 2026

    Additionally, you can go through below technical tip.