Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jefeson
New Contributor

How to block ICMP flood

Hello my friends, How to block an flood with these parameters: sudo hping3 -q -n -a 10.0.0.1 --id 0 --icmp -d 9999 --flood 192.168.20.1 Thanks Jefeson Alves
Jefeson Alves Infrastructure Analyst IT
Jefeson Alves Infrastructure Analyst IT
3 REPLIES 3
Jefeson
New Contributor

Does anyone have a good practice to be configured on the FortiGate? Jefeson Alves
Jefeson Alves Infrastructure Analyst IT
Jefeson Alves Infrastructure Analyst IT
Matthijs
New Contributor II

Within IPS create a dos sensor with icmp_flood enabled, action pass, and set some threshold. Enable logging to see it matches. Try to play with the threshold until it hits when you want it to and then change action to block. You might also start blocking it right away, but when you guessed the wrong threshold, this might lead to unexpected problems like dropping " normal" traffic ;-) Use the dos policy under firewall -> policy -> dos policy
Jefeson
New Contributor

It' s recomended disable ping on the interface? Thanks Jefeson Alves
Jefeson Alves Infrastructure Analyst IT
Jefeson Alves Infrastructure Analyst IT
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors