Question
Help with external Scan
I have a FortiGate 80C and the Intrusion Protection is stopping me from running an external compliance scan against my devices. I have a range of IP' s that I would like to be able to fully scan my webservers; however, the Intrusion Protection drops the scan. My scans end up failing thinking that either A) I am vulnerable to a DOS attack, or B) It fails because it can' t complete the scans. What I have done so far - I created a Policy rule from my External scan range to Internal Any, on Any service port. In addition, I have turned the Intrusion Protection to " Monitor All" , but even when I did this the log would show that things were being dropped. I have since removed my IPS Sensor, but the log report for IPS Packet Archive is still showing that it is dropping things. Is there something else I should be doing? Any idea on how to allow these scans? Thanks in advance!
