FortiOS 6.0.2- IPv4 DoS Policy
Hi Everyone,
I'm running FortiOS 6.0.2 on a Fortigate 60E and having a few issues with IPv4 DOS Policies.
I've exposed an NTP server to the Internet and added into the NTP Pool.
However, as you might expect, I'm seeing a few issues from users/ systems who just wont play nice and are triggering my existing IPv4 WAN side DoS policy.
I'd like to fine tune the behaviour here a little so have a couple of specific questions:-
1. Can I run more than one DoS policy on an interface (eg one specifically for an NTP server/ service)? (I presume the answer is yes, but my experiements here so far have been unsuccessful- the new NTP DoS policy never seems to get triggered and the main WAN policy is getting hit all the time. Again, my assumption is that the order of the policies is important, but even moving the new NTP policy to the top of the list it doesn't seem to get hit).
2. Under 6.0.2 I don't seem to be able to change the quarintine time for a source IP that triggers the DoS policy. I would like to increase it from the 1 hour setting, but despite applying the changes from CLI it doesn't appear to change or apply (I am the only admin on the system- so not a question of user rights....).
3. I'm set for email alerts on the Fortigate for Critical events. Every NTP DoS attack is currently triggering an email. Is there an easy way to prevent these alerts being genrated for a specific DoS policy or specific anomoly? (This would be even better if I could get a separte NTP server/ service DoS policy working and then ignore most alerts for that).
Thanks for any help or suggestions you are able to offer.
Kind Regards,
Andy.