Hi,
I´m having a problem with the new signature "name_server: DNS.PTR.Records.Scan". The signature is generating a lot of logs entries, and any of them is an real attack.
I´m trying to disable it from my Sensor, but even though I disable this signature, disable the logs from it (Over CLI), but the FortiGate ignores the settings, and continues showing a lot of the logs.
Someone can help-me please.
Solved! Go to Solution.
Can you show us the current configuration of the IPS sensor profile? (i.e. close the "add signatures panel" and show us the rest of the profile's config)
Reasoning: The signature/filter rules are applied top-down as they appear in the list. Maybe you're adding this DNS.PTR.Records.Scan override below an existing rule that handles this signature differently? (e.g. using its default settings) If this is the case, the solution might be as simple as dragging the specific DNS.PTR.Records.Scan rule above the other existing rule(s) in the GUI.
Can you show us the current configuration of the IPS sensor profile? (i.e. close the "add signatures panel" and show us the rest of the profile's config)
Reasoning: The signature/filter rules are applied top-down as they appear in the list. Maybe you're adding this DNS.PTR.Records.Scan override below an existing rule that handles this signature differently? (e.g. using its default settings) If this is the case, the solution might be as simple as dragging the specific DNS.PTR.Records.Scan rule above the other existing rule(s) in the GUI.
Shame on Me... That was the problem.
Thanks a Lot
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.