Skip to main content
FClient_User
New Member
May 19, 2018
Question

Need help identifying if my system was accessed by intruders through forticlient

  • May 19, 2018
  • 6 replies
  • 5855 views

Hi,

 

I connect my home computer running windows 8 pro with forticlient to a network and then work on the computer there. Could someone please guide me if there is a possibility of my home computer getting accessed and files read or uploaded out? Can someone with my own forticlient password or administrator password gain access to my home computer? If yes is there a log where I can find it? I can upload the logs if you want. Much thanks!

 

 

 

Thanks,

FCUser

    6 replies

    ede_pfau
    SuperUser
    SuperUser
    May 20, 2018

    hi,

     

    there is no way to establish the tunnel from remote. But, if the tunnel already is up while you're working, you've essentially got a direct connection between your PC and the remote LAN.

    FC has a built-in firewall and maybe you've got other security software on your PC like Kaspersky which features one. If that is active you can control access from remote.

    If access from remote to your PC is allowed then one could create a connection to a local share ('net use x: \\myPC\share') and copy files from and to. That is independent of the VPN though.

    Logging: there is no valuable log info from the FC regarding file copies. You may find these in the Windows logs if configured (file or folder monitoring).

    emnoc
    New Member
    May 20, 2018

    Why do you ask? Want drove you to  this speculation? As far as logs are you looging anything on the fortigate? What's fw.policy for the remote-access? What network/server resource do you allow for the "remote users" ( SMB/CIFS, RDP,FTP, etc...) ? I would  be more incline to review the logs on the server resource if any than the firewall, since the logs at the firewall will just show you traffic and not failed logins,logins, etc....

     

    YMMV

    FClient_User
    New Member
    May 22, 2018

    ede_pfau wrote:

    hi,

     

    there is no way to establish the tunnel from remote. But, if the tunnel already is up while you're working, you've essentially got a direct connection between your PC and the remote LAN.

    FC has a built-in firewall and maybe you've got other security software on your PC like Kaspersky which features one. If that is active you can control access from remote.

    If access from remote to your PC is allowed then one could create a connection to a local share ('net use x: \\myPC\share') and copy files from and to. That is independent of the VPN though.

    Logging: there is no valuable log info from the FC regarding file copies. You may find these in the Windows logs if configured (file or folder monitoring).

    Hi ede,

    I dont have any other security software. So will the Fc's built in firewall prevent anyone in the remote LAN to access the files on my PC? I just checked, my PC has "Don't allow remote connections to this computer" checked.

    Where are these windows logs for file and folder monitoring?

     

     

    emnoc wrote:

    Why do you ask? Want drove you to  this speculation? As far as logs are you looging anything on the fortigate? What's fw.policy for the remote-access? What network/server resource do you allow for the "remote users" ( SMB/CIFS, RDP,FTP, etc...) ? I would  be more incline to review the logs on the server resource if any than the firewall, since the logs at the firewall will just show you traffic and not failed logins,logins, etc....

     

    YMMV

    I have a strong suspicion someone in the remote LAN or someone connected to the remote LAN was spying on me. I think its a group effort of 2 or more people, with one having admin access. Can this admin delete the logs on the fortigate or will the logs be secure? Can they tamper with the server side logs?

    Where can i view the firewall logs?

    I've been trying desperately to find out what really happened. I really need help on this, please!

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!