hi all, My fortigate (310B) is receiving a very high input traffic on interface facing the internet, but there are a little traffic on inside interface(facing Lan network), i am afraid of someone is attacking or scan port to my fortigate. So which CLI command can I use to list the IPs attacking to my FG devices or any threat FG is receiving? or any advice to check and debug my problem ? Thanks,
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
anyone help me, please !
hmmm...if I would scan for open ports on your public IP, would I'd be successful? If not, don't worry. Connection attempts are not as much a burden as incoming traffic, except for a DoS situation so that legitimate traffic cannot connect anymore.
You've got the logging ('denied traffic') to find out which kind of traffic you're seeing. If you don't serve that port, all the better. If you do, have a look at 'local-in' policies, to deny specific traffic from ip address ranges or geo locations (countries) etc. Local-in policies are handled first so you'd economize on CPU load.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1561 | |
1034 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.