I have an Remote Desktop Services (RDS) Gateway service running on port 443. I am trying to implement IPS rules on FortiOS 7.4.8 that block unsuccessful attempts at logging in. I can see in the HTTP/IIS logs that a 403 unauthenticated code is given when users enter an incorrect password.
I tried leveraging the HTTP.Authentication.Brute.Force policy and configuring it with a threshold of 3 for a duration of 60 seconds but that did not seem to work.
I then proceeded to create a custom rule (below), however it yielded the same results.
F-SBID( --attack_id 1870; --name \"HTTP.401.Unauthorized.Multiple\"; --service HTTP; --protocol TCP; --pattern \"401 Unauthorized\"; )
Does anyone know how to configure the IPS to detect unsuccessful login attempts against an RDS GW server?
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Thanks,
Hello,
To configure FortiGate IPS for monitoring RDS Gateway traffic, follow these steps:
| User | Count |
|---|---|
| 2829 | |
| 1433 | |
| 812 | |
| 789 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.