Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezafathi
Contributor II

Block inside attacks

Hello

How can i block inside attacks like portscan or other attacks with fortigate inside my Lan?

Reza F.
Reza F.
6 REPLIES 6
ebilcari
Staff
Staff

There are two possible ways as shown also in this article:

- application control with custom signatures

- configuring a DoS policy

More general information can also be found here.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
rezafathi

Thanks. How can i find each application signature and use it in app control?

Reza F.
Reza F.
Sheikh
Staff
Staff

Hello @rezafathi 

This would also help in application detection and control.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-check-Application-Control-category-...

 

regards,

 

Sheikh

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
AEK
SuperUser
SuperUser

Hi Reza

Try to configure a new IPS profile that blocks the below signature (Port.Scanning), then use it in your firewall policy.

Note that the default action for this signature is "Allow", that's why it is not blocked in the default IPS profiles.

ips_scan.png

AEK
AEK
rezafathi
Contributor II

I can not find this signature

Reza F.
Reza F.
AEK

Make sure your IPS signatures are updated.

diagnose autoupdate versions

 

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors