1. Am I protecting the Starttech IPs? - assume the IPS profile is correct. (Yes/No)
2. Am I letting all other IPs go through with just ' regular' firewall services? - assume my policies are correct. (Yes/No).
My previous Setup had the Firewall rule ID 3 BEFORE ID6 (as shown in my picture).
I have just swapped them, so ID-6 is now showing First - so the picture is showing the Current status.
3. Is this how I should have it?
4. Was the previous order a mistake? (where ID-3 came before ID-6).
Thanks for any input on this.
-Sup.
PCNSE
NSE
StrongSwan
anomaly: tcp_src_session, 71 > threshold 70, repeats 29 timesOH,. I wasn' t concerned about the " tcp_reassembler: TCP.Stealth.Activity, paw" I don' t care for that one,. I do see those, but actually not that many. My primary concern is this one: " anomaly: tcp_src_session, 71 > threshold 70, repeats 29 times " Over 70 sessions from a single source seems to me very unlikely as a normal activity. But perhaps I' m wrong? When you visit a website, a forum, etc,. should you have more then 70 sessions originating from YOUR compuer to the Server? That is to my understanding an attack of some sort. That needs to be blocked.
| User | Count |
|---|---|
| 2686 | |
| 1412 | |
| 810 | |
| 704 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.