Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
seadave
Contributor III

Quarantine not working

Running a 100D on 5.2.2, just updated to 5.2.3.  I have IPS rules setup to quarantine IPs but they stopped working about two weeks ago.  I thought updating to 5.2.3 might fix but I'm not see any IPs that trigger IPS rules set to quarantine being added to the list.

 

The other issue I had was with updated IPS definitions being added to existing lists.  The:

 

MS.Windows.HTTP.sys.Request.Handling.Remote.Code.Execution

 

vuln is pretty serious and we had one server that should have been protected by that signature have an attempted exploit launched at it.  An upstream MSP detected the attempt.  So when I checked on the IPS sigs my Fortinet was enforcing for that connection; despite me having selected "Server" and "Windows" for the criteria, this IPS sig was not enabled.

 

It appears it falls under the "Server", "Windows", and "Other" for Application.  But if you enable "Other" the filter pulls all sorts of stuff like AOL that doesn't apply to my server.  If someone can explain the logic behind how the IPS sigs are selected based on categories selected, that would be great.

 

Wondering if anyone else has seen these issues.

1 REPLY 1
emnoc
Esteemed Contributor III

Let's go back to the quarantine or lack of, are you sure the sensor is still applied to the policy and the traffic is matching that policy? & the action is quarantine ?

 

I know others have had issues with policies ( not me ) when upgrading but I would check that and any ordering. Maybe generating some traffic to cause the sensor to match and diag debug flow my shed some light on this problem.

 

FWIWl I spent 2 days ago with a client of mine  who disabled a fwpolicy & I only found the issues after he grant us remote access, so make sure the policy was not set status disable

 

next, can you explain better on the last problem? I'm not quite following you.

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors