Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mtousignant
New Contributor

RST send from Fortigate causing false positives in nexpose

Due to the Fortigates Anti-Replay features; it will send RST for non-existent IPs as Nexpose tries to discover (Nexpose is a vulnerability scanner). 

 

Example - note, there is nothing on 192.168.230.190 in my network: 

017-01-09 16:31:18.946212 VLAN201 -- 192.168.201.15 -> 192.168.230.190: icmp: echo request 2017-01-09 16:31:18.946300 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.21: syn 2847265423 2017-01-09 16:31:18.946343 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.22: syn 2847265423 2017-01-09 16:31:18.946378 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.23: syn 2847265423 2017-01-09 16:31:18.946411 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.25: syn 2847265423 2017-01-09 16:31:18.946444 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.53: syn 2847265423 2017-01-09 16:31:18.946477 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.80: syn 2847265423 2017-01-09 16:31:18.946510 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.88: syn 2847265423 2017-01-09 16:31:18.946543 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.110: syn 2847265423 2017-01-09 16:31:18.946962 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.111: syn 2847265423 2017-01-09 16:31:18.949091 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.113: syn 2847265423 2017-01-09 16:31:18.949139 VLAN201 -- 192.168.230.190.113 -> 192.168.201.15.55755: rst 0 ack 2847265424 2017-01-09 16:31:18.978576 VLAN201 -- 192.168.201.15.56011 -> 192.168.230.190.21: syn 3135253229 2017-01-09 16:31:18.978649 VLAN201 -- 192.168.201.15.56011 -> 192.168.230.190.80: syn 3135253229

 

From what I understand setting Anti-replay to loose or disabled will resolve this. 

 

Is there any way to achieve this on a per policy, per interface, per vdom etc rather then a global setting? Some way of achieving this result that isn't a global parameter opening up the box to syn attacks? 

 

0 REPLIES 0
Labels
Top Kudoed Authors