Does anyone know how to disable ICMP timestamp replies from FortiAPs? My FortiAPs are connected to my LAN, and I have Fortiswitches. Polices do not seem to work - my guess is because the traffic is being routed by the switches and not going through the firewall?
If I'm not wrong the an ICMP timestamp reply is a response to an ICMP timestamp request, right?
In that case then you just need to add a firewall rule to deny ICMP requests from the desired source to the FortiAPs.
This is because I don't know a way to allow ICMP requests and in the same time to deny ICMP replies. As far as I know this is how stateful firewalls are designed.
For some reason, that does not work. I am wondering if it is because the APs and the host are on the same LAN, and therefore the traffic is not routed through the Fortigate.
It wouldn't go through the FGT. It's directly sent to AP by MAC address found in ARP.
Toshi
You’re right — since the APs and host are on the same LAN, the traffic won’t pass through the FortiGate, so its policies won’t apply.
Then I guess it is possible just by disabling the ping on the related SSID interface.
I think it's about FAP's management interface, not SSIDs.
Toshi
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.