Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
lucas85
New Contributor

DoS-Banned-IP

Hello, I've got question about Denial policy in Fortigate. I put set up for DoS on my Wan IP with test thresholds like some examples below; 

 

 config anomaly
            edit "icmp_flood"
                set status enable
                set log enable
                set action block
                set quarantine attacker
                set quarantine-expiry 15m
                set quarantine-log enable
                set threshold 100

 Now when I put some nmap scan from outside network to my WAN IP I get banned my IP address is putted on quaranteen list but even tough I can still ping WAN IP and I don't know why ? 

1 Solution
gfleming

So this is all normal behaviour. A banned-ip (quarantine) will still be able to ping the FW WAN interface. As metnioned in the doc I posted earlier, "The banned user list is kept in the kernel, and used by Antivirus, Data Leak Prevention (DLP), DoS, and Intrusion Prevention System (IPS). Any policies that use any of these features will block traffic from the attacker's IP address."

 

Pinging the WAN IP does not involve any FW policies (it is local-in traffic).

 

The DDOS profile will continue to block ICMP floods, however.

Cheers,
Graham

View solution in original post

5 REPLIES 5
gfleming
Staff
Staff

Fairly certain quarantined IP addresses are only checked in firewall policies which are only checked in forwarded traffic not local-in traffic.

https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/771644/dos-policy#Quaranti

Cheers,
Graham
lucas85

I get confused because in tutorials on Youtube with the same config when someone put flood icmp on WAN IP from outside get blocked and in my not.

 

gfleming

Does that tutorial show it getting blocked on the WAN interface or on a FW policy? Can you share the tutorial?

Cheers,
Graham
lucas85

https://www.youtube.com/watch?v=bGffZFPM5rU&ab_channel=EwakoNetwork

 

This one when he start attack it get banned and flood is stopped.

In my case I get banned IP from external network but even tough I still can ping.

gfleming

So this is all normal behaviour. A banned-ip (quarantine) will still be able to ping the FW WAN interface. As metnioned in the doc I posted earlier, "The banned user list is kept in the kernel, and used by Antivirus, Data Leak Prevention (DLP), DoS, and Intrusion Prevention System (IPS). Any policies that use any of these features will block traffic from the attacker's IP address."

 

Pinging the WAN IP does not involve any FW policies (it is local-in traffic).

 

The DDOS profile will continue to block ICMP floods, however.

Cheers,
Graham
Labels
Top Kudoed Authors