- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Block Client ID Fortiweb
Regards,
We need to be able to "automatically" block Client IDs that exceed a Threat Score by some policy or rule in Fortiweb 6.3
Thank you
- Labels:
-
FortiWeb
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@JMATAS You can add the following entry under the Client management configuration>Block Settings to block Malicious Client(Client with the histrorcal threat =>200 for a certain period.
Please ensure you have enabled the 'Client management' in the Web Protection profile applied to the server policy.
Test Results:
These screenshots are from 6.3.22 GA Fortiweb.
Please refer to the following admin guide link for further information.
Created on ‎05-03-2023 01:05 AM Edited on ‎05-03-2023 01:06 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you very much Denzil, it is one of the things we are doing, controlling the attack with the limits of the Client Management Configuration, but the blocking limits are at most one day, the boots reappear after that time.
We would like to know, then, how to block those Client IDs once they exceed a Historical Threat Weight set by us.
Thank you so much.
