Hello, I've got question about Denial policy in Fortigate. I put set up for DoS on my Wan IP with test thresholds like some examples below;
config anomaly edit "icmp_flood" set status enable set log enable set action block set quarantine attacker set quarantine-expiry 15m set quarantine-log enable set threshold 100
Now when I put some nmap scan from outside network to my WAN IP I get banned my IP address is putted on quaranteen list but even tough I can still ping WAN IP and I don't know why ?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
So this is all normal behaviour. A banned-ip (quarantine) will still be able to ping the FW WAN interface. As metnioned in the doc I posted earlier, "The banned user list is kept in the kernel, and used by Antivirus, Data Leak Prevention (DLP), DoS, and Intrusion Prevention System (IPS). Any policies that use any of these features will block traffic from the attacker's IP address."
Pinging the WAN IP does not involve any FW policies (it is local-in traffic).
The DDOS profile will continue to block ICMP floods, however.
Fairly certain quarantined IP addresses are only checked in firewall policies which are only checked in forwarded traffic not local-in traffic.
https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/771644/dos-policy#Quaranti
I get confused because in tutorials on Youtube with the same config when someone put flood icmp on WAN IP from outside get blocked and in my not.
Does that tutorial show it getting blocked on the WAN interface or on a FW policy? Can you share the tutorial?
https://www.youtube.com/watch?v=bGffZFPM5rU&ab_channel=EwakoNetwork
This one when he start attack it get banned and flood is stopped.
In my case I get banned IP from external network but even tough I still can ping.
So this is all normal behaviour. A banned-ip (quarantine) will still be able to ping the FW WAN interface. As metnioned in the doc I posted earlier, "The banned user list is kept in the kernel, and used by Antivirus, Data Leak Prevention (DLP), DoS, and Intrusion Prevention System (IPS). Any policies that use any of these features will block traffic from the attacker's IP address."
Pinging the WAN IP does not involve any FW policies (it is local-in traffic).
The DDOS profile will continue to block ICMP floods, however.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.