Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
andreotta
New Contributor

NMAP

Hello people, I´m enable the IPS and DOS Sensor to log and block syn flood, and port scan, I check the logging option and the block option. But, when I run NMAP, the FG not block and not log in UTM logs or event logs. Anyone have an idea ? Regards, André Otta
4 REPLIES 4
mafton
New Contributor

1-Enter a small number for each anomaly (for example 1) then when you are scanning ip addresses , logs can be generated . however you have to select appropriate Thresholds for each one. 2-Be sure that you write DoS policy . also you can quarantine attackers ip address , with cli commands
Norozi
Norozi
andreotta

Thanks for help Mafton. I set the one for threshold, and create a dos policy. WAN 1 for Interface ALL for Source Addr ALL for Destination Addr ANY for SERVICE Check the DOS sensor, and select NMAP( I created with thresold = 1) I´m doing a external SCAN, in WAN1 ip. But, UTM logs are empty....and no logs about these in event logs... Can you help me ? Thanks again! Regards André
mafton
New Contributor

1- Did you enable Logging in DoS sensor? 2- Is there any virtual ip with the WAN1 ip address?
Norozi
Norozi
andreotta

Yes I enable. No, there´s not a virtual IP in WAN1. Fortinet support says: Update the firmware to 4 MR3 patch 10, and " Sniffer policies can only be configured when the one-arm sniffer option is enabled." But, I can´t enable sniffer in wan1 interface, right ? The manual says: If sniffer enabled in the interface, you can´t use interface for anymore. My prolem not solved, and my ticket is open. Thanks.
Labels
Top Kudoed Authors