Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jefeson
New Contributor

How to block ICMP flood

Hello my friends, How to block an flood with these parameters: sudo hping3 -q -n -a 10.0.0.1 --id 0 --icmp -d 9999 --flood 192.168.20.1 Thanks Jefeson Alves
Jefeson Alves Infrastructure Analyst IT
Jefeson Alves Infrastructure Analyst IT
3 REPLIES 3
Jefeson
New Contributor

Does anyone have a good practice to be configured on the FortiGate? Jefeson Alves
Jefeson Alves Infrastructure Analyst IT
Jefeson Alves Infrastructure Analyst IT
Matthijs
New Contributor II

Within IPS create a dos sensor with icmp_flood enabled, action pass, and set some threshold. Enable logging to see it matches. Try to play with the threshold until it hits when you want it to and then change action to block. You might also start blocking it right away, but when you guessed the wrong threshold, this might lead to unexpected problems like dropping " normal" traffic ;-) Use the dos policy under firewall -> policy -> dos policy
Jefeson
New Contributor

It' s recomended disable ping on the interface? Thanks Jefeson Alves
Jefeson Alves Infrastructure Analyst IT
Jefeson Alves Infrastructure Analyst IT
Labels
Top Kudoed Authors