Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kinmun
New Contributor II

Qualys PCI scanning failed

We do PCI scanning regularly on a monthy basis.

A recent failed with the following error message

Threat:

The filtering device doesn't block spoofed IP packets. Packets going to the external firewall interface with internal network IP addresses seem to be accepted. 

 

recommendation is that we do the following

Change your firewall policy to deny packets coming on the external interface with a source IP from the internal network. You should also deny packets on the external interface with a source IP that is non-routable, such as 10.0.0.1 or 127.0.0.1.

 

what should I do?

 

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors