Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kenundrum
Contributor III

One arm sniffer filtering

I have a one arm sniffer configured on a fortigate and it works quite well. The only problem is that is detecting vulnerability scans as intrusion attempts. The filters appear to operate in a whitelist only mode. Scan traffic to/from these hosts/ports/vlans etc, drop everything else. Is there a way to blacklist? I want to configure the filter to sniff and scan everything EXCEPT a certain host. There has to be a better way than doing something along the lines of filter 1.1.1.1-10.10.10.9,10.10.10.11-254.254.254.254 (thus excluding 10.10.10.10 for example)

CISSP, NSE4

 

CISSP, NSE4
0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors