Skip to main content
filiaks1
Explorer III
June 15, 2025
Question

Is there are forti product that monitors the server response latency or response codes for auto DOS?

  • June 15, 2025
  • 5 replies
  • 1135 views

Hi,

 

After reviewing the forti demos at https://www.fortinet.com/demo-center and the documentation and some trainings I wondered what layer 3/4 and expecially layer 7 HTTP auto DOS protections are available without configuring manual thresholds in FortiDDos, FortiWeb, FortiADC ?

 

I mean like by triggering DOS protection based on the web server latency in HTTP responses or web server starting to return more 5xx response codes ?

 

I beliave that only fortiDOS offers auto thresholds as in the HTTP profile I see no manual thresholds like in FortiWeb or FortiADC but if I could get a confirmation?

 

Screenshot 2025-06-16 010933.png

 

 

Screenshot 2025-06-17 104649.png

5 replies

shafiq23
Staff & Editor
Staff & Editor
June 17, 2025

Hello @filiaks1,

 

I believe a Custom Policy in FortiWeb would be some sort of threshold control for such scenario. 

 

1. Match range 5XX return codes

2. Define occurrences in specific time period

 

custom-policy.png

 

Thanks.


Regards,
Shafiq

filiaks1
filiaks1Author
Explorer III
June 17, 2025

Not a bad idea @shafiq23  and the custom policy can track more than just IP address like user and session. Still it is not dynamic as I would have hoped but it is there. Probably TCL script can do the same but custom policy seems more readable as scripting I saw is also in FortiADC but not the custom policy.

 

 

 

Screenshot 2025-06-17 104758.png

 

Outside of that I saw that fortiddos is uses auto behavioral thresholds that are based on the number of http packets that are expected in a particular time window not the server latency/response codes.

filiaks1
filiaks1Author
Explorer III
June 18, 2025

Extra note during DDOS the servers can stop replying or send 503 like Nginx and after playing with the Custom Policy unfortunatly this is more to block attackers that trigger 5xx errors @shafiq23 not for triggering DOS protections?

 

Maybe if everyone could start getting javascript or captcha checks if many 5xx errors are seen with a custome policy or TCL script  config not just the user generating the current traffic as they could be not attackers even if they get 5xx because of the server utlization?

 

Also what you showed with the custom policy and response codes I think the FortiWeb ML can do this automatically FortiWeb Bot Protection: Machine Learning based Protection 

 

 

An extra question @shafiq23  is FortiWeb Bot needing javascripts as if the traffic is API? I think only biometric and deception need a javascript?

 

 

 

 

 

 

Screenshot 2025-06-18 133631.png

Screenshot 2025-06-18 134044.png

 

shafiq23
Staff & Editor
Staff & Editor
June 20, 2025

Hello @filiaks1,

 

ML based bot detection is also a good approach to detect deviation of HTTP error responses(return codes larger than 400). 

Previous sample custom policy is used to statically block occurrences of HTTP 5XX responses - it might block legitimate requests.

 

From my understanding, js is inserted when Bot Confirmation is enabled and if the response is is HTML. 

 

Thanks.

 

Regards,

Shafiq

filiaks1
filiaks1Author
Explorer III
June 23, 2025

This will not be anabled for API traffic that much I am aware of as this checks if you are a browser and we don't want that. Also the response will not be html for API but thanks for confirming this detection by FortiWeb.

 

Configuring bot detection policy | FortiWeb 7.0.1 | Fortinet Document Library

 
 

Screenshot 2025-06-23 102446.png

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.