Hi, I'm facing the following issue. On our fortigate 110C I'm observing a lot of traffic originated from an email account. This email account was frauded and someone is trying to register it with wrong password on our servers in the locale network generating a lot of traffic.
Unfortunately we can't block this account because is in use every day by our customer. So I tried to use the IPS sensor in default mode but no mails are delivered. How can I configure the IPS sensor in order to block the malicious traffic and permit the right traffic? Could you please give some advice? In this situation we have the firewall CPU at 100%
Thanks.
Ricky
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
How did you test this? Can you continue attempting logins after the second try?
The signatures look OK IMHO. I think I remember that the name of the signature should be identical to the '--name' option, and yours aren't. You might try this out.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1640 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.