Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ricky76
New Contributor

Large traffic by a frauded account email - IPS how to use

Hi, I'm facing the following issue. On our fortigate 110C I'm observing a lot of traffic originated from an email account. This email account was frauded and someone is trying to register it with wrong password on our servers in the locale network generating a lot of traffic.

Unfortunately we can't block this account because is in use every day by our customer. So I tried to use the IPS sensor in default mode but no mails are delivered. How can I configure the IPS sensor in order to block the malicious traffic and permit the right traffic? Could you please give some advice? In this situation we have the firewall CPU at 100%

 

Thanks.

Ricky

10 REPLIES 10
ede_pfau

How did you test this? Can you continue attempting logins after the second try?

 

The signatures look OK IMHO. I think I remember that the name of the signature should be identical to the '--name' option, and yours aren't. You might try this out.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors