60e 6.4.9 reports CVE 1999-0525 Trace Route IPS attack on my workstation. I have ran Avast full scan and Malwarebytes found nothing. I did see in the CVE it was updated 6/9/22. I am trying to disable Traceroute in the IPS. I added a Traceroute policy to disable it in IPS. I moved it to the top of the IPS list and excluded just my IP.
Hello,
Looking at the count detection bellow:
https://www.fortiguard.com/encyclopedia/ips/12466
After the signature update, there is a peak. It is quite possible to be a false positives after the signature was updated (or there was false negative before the update)
To "disable" it simply put a filter for attack ID 12466 with action "pass"
@metz_FTNT wrote:Looking at the count detection bellow:
Hi, where is the count detection, I don't see them?
At the time when I posted the link, there was a telemetry on the bottom of the page showing the graph for counting detection of the signature. There was a high peak just at the same time when the signature was updated.
Here was my solution. I placed Trace Route at the beginning of the rules. I added my workstation IP as an exclusion
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.