FortiDDoS
FortiDDoS protects from both known and zero day attacks with very low latency. It’s easy to deploy and manage, and includes comprehensive reporting and analysis tools.
arleniscg
Staff
Staff
Article Id 381849
Description This article describes the troubleshooting steps if monitoring logs show traffic blocked in relation to IP Reputation or Domain Reputation.
Scope FortiDDoS-F.
Solution
  1. Validate the device has IP Reputation included on the associated license, that the reputation is active, and that the database date has been updated under System -> FortiGuard -> IP Reputation (see this document: IP Profile).

 

FDD KB.png

 

  1. If the license is expired or FortiDDoS does not have it included, the IP Reputation or Domain Reputation must not be active under any SPP (if not subscribed, never enable IP Reputation (IP Reputation) or Domain Reputation).

 

FDD Lic expire or FortiDdoS license doesn't incloude IPreputation.png

 

 

FDD profile 01.png

 

 

FDD profile 02.png

 

Important notes:

Before FortiDDoS v7.0:

  1. A small default IP Reputation database was included in the software.
  2. If IP Reputation/Profile is enabled without a valid license, traffic drops will occur.
  3. If a device had an active IP Rep subscription that later expired and the feature was left enabled, traffic drops will occur unless the feature is explicitly disabled.

 

Starting from FortiDDoS v7.2.0:

  1. No default IP Rep database is included in the software.
  2. If the subscription expires, the database is removed.

If further support is needed, open a case with the Fortinet TAC Team.

 

Related article:

Technical Tip: FortiDDoS commands to open a new ticket to TAC