Hello,
thats a strange issue we have some time now after updating from FG81E to FG90G and it also only happens in one office. It is true, that there are main users (max 40) using Teams.
Before with the FG81 we didnt have the problems. Now we use SD WAN for the FG90G and implicit SD WAN rule with Volume and 99% using our Internet Access A. Though we have also above a SD WAN Rule with destination Microsoft-Skype_Teams, Microsoft-Teams.Published.Worldwide.Optimize and Microsoft-Teams.Published.WorldwideOptimize.Allow for Internet Access A.
We tried with dedicated Firewall Policy with ALL services and no Security Profile for these 3 destinations - with no better results.
Than we tried to Bypass our DoS Policy with new policy above to only Monitor Teams UDP Ports (3478-3481 - 49152-65535) - with no better results.
Only disabling the DoS Policy for out Internet Access A seems to solve the problem but since I dont want to have no DoS on this interface what can we do?
Thanks!
Hello Roland,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Sorry that cannot answer your question, but speaking from experience and for the benefit of others - Fortigate built-in DDoS will only bring pain without much gain. It is not behavior-based, nor learning, nor adapting. It is a basic incoming packets rate filter that you have to set threshold value beforehand and this will cause sooner or later outages when the traffic spikes for legit reasons. And the way DDoS attacks work makes any protections set on perimeter device pretty much useless, regardless of the vendor. ICMP/UDP/etc connectionless flood will saturate the ISP line up to the Fortigate making 0% bandwidth available and Fortigate will have nothing against it, for users the line will be down.
I am Bill from Fortinet, I would like reproduce your issue in my lab. Could you please share the configuration to my official email ? bhoang@fortinet.com. Or if you already have ticket pls share the number with me I could take the cfg from ticket. Thank you
Bill
| User | Count |
|---|---|
| 2808 | |
| 1427 | |
| 812 | |
| 769 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.