Due to the Fortigates Anti-Replay features; it will send RST for non-existent IPs as Nexpose tries to discover (Nexpose is a vulnerability scanner).
Example - note, there is nothing on 192.168.230.190 in my network:
017-01-09 16:31:18.946212 VLAN201 -- 192.168.201.15 -> 192.168.230.190: icmp: echo request 2017-01-09 16:31:18.946300 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.21: syn 2847265423 2017-01-09 16:31:18.946343 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.22: syn 2847265423 2017-01-09 16:31:18.946378 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.23: syn 2847265423 2017-01-09 16:31:18.946411 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.25: syn 2847265423 2017-01-09 16:31:18.946444 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.53: syn 2847265423 2017-01-09 16:31:18.946477 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.80: syn 2847265423 2017-01-09 16:31:18.946510 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.88: syn 2847265423 2017-01-09 16:31:18.946543 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.110: syn 2847265423 2017-01-09 16:31:18.946962 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.111: syn 2847265423 2017-01-09 16:31:18.949091 VLAN201 -- 192.168.201.15.55755 -> 192.168.230.190.113: syn 2847265423 2017-01-09 16:31:18.949139 VLAN201 -- 192.168.230.190.113 -> 192.168.201.15.55755: rst 0 ack 2847265424 2017-01-09 16:31:18.978576 VLAN201 -- 192.168.201.15.56011 -> 192.168.230.190.21: syn 3135253229 2017-01-09 16:31:18.978649 VLAN201 -- 192.168.201.15.56011 -> 192.168.230.190.80: syn 3135253229
From what I understand setting Anti-replay to loose or disabled will resolve this.
Is there any way to achieve this on a per policy, per interface, per vdom etc rather then a global setting? Some way of achieving this result that isn't a global parameter opening up the box to syn attacks?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.