Hi all
I'm getting the following, I am aware also what is causing it (a known internal security scan), how can i DISABLE getting notified about these "IP.Unknown.Option" alerts? can someone point me to the right cli commands (or gui settings) Its a fg200b running 5.2.13
Message meets Alert condition
The following intrusion was observed: IP.Unknown.Option.
date=2020-07-25 time=21:38:55 devname=XXXXXX devid=XXXXXX logid=0720018432 type=anomaly subtype=anomaly level=alert vd="root" severity=critical srcip=XXXXXX srccountry="Reserved" dstip=XXXXXX srcintf="XXXXXX" sessionid=0 action=dropped proto=6 service=HTTP count=2 attack="IP.Unknown.Option" srcport=33753 dstport=80 attackid=108 ref="http://www.fortinet.com/ids/VID108" msg="anomaly: IP.Unknown.Option, repeats 2 times" crscore=50 crlevel=critical
i tried this but didnt work (from another website)
config ips sensor
edit "IP.Unknown.Option"
config entries
edit 1
set rule 180
set log disable
next
end
next
end
Hi fsmar,
Can check the following docs:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD33609
darwin wrote:Hi fsmar,
Can check the following docs:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD33609
I dont think it is the same case, can you tell me more about it? I dont see there any documentation on how to disable these notifications
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.