Hi all
I'm getting the following, I am aware also what is causing it (a known internal security scan), how can i DISABLE getting notified about these "IP.Unknown.Option" alerts? can someone point me to the right cli commands (or gui settings) Its a fg200b running 5.2.13
Message meets Alert condition
The following intrusion was observed: IP.Unknown.Option.
date=2020-07-25 time=21:38:55 devname=XXXXXX devid=XXXXXX logid=0720018432 type=anomaly subtype=anomaly level=alert vd="root" severity=critical srcip=XXXXXX srccountry="Reserved" dstip=XXXXXX srcintf="XXXXXX" sessionid=0 action=dropped proto=6 service=HTTP count=2 attack="IP.Unknown.Option" srcport=33753 dstport=80 attackid=108 ref="http://www.fortinet.com/ids/VID108" msg="anomaly: IP.Unknown.Option, repeats 2 times" crscore=50 crlevel=critical
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
i tried this but didnt work (from another website)
config ips sensor
edit "IP.Unknown.Option"
config entries
edit 1
set rule 180
set log disable
next
end
next
end
Hi fsmar,
Can check the following docs:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD33609
darwin wrote:Hi fsmar,
Can check the following docs:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD33609
I dont think it is the same case, can you tell me more about it? I dont see there any documentation on how to disable these notifications
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1720 | |
1094 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.