Can anyone explain why I am seeing this "Top Threat" from IP's in my own network?
(What could be causing this?)
Thanks,
-Tom
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I haven't found the official definition, but from what I've concluded is this means any traffic that was allowed through the firewall, but did not form a complete connection. It might also be tied to the session table timer. For example, if a device on the network tries to open a tcp session with another device through the firewall, but the receiving device isn't listening on the given port. Could be indicative of a misconfigured host, application, or a scan. You'd have to investigate to be sure.
I just set the threat weight to 0 as it was mostly junk. Again I'm not entirely sure but it looks like anything that times out of the session table gets this label, including UDP. I found it to be too noisy to be of any good and effectively disabled it in FortiView. You'll still see IP Connection error in the logs though, so its not like you are completely disabling the logging of this traffic.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.