Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
It is not entirely true that you can't ban IP sources, albeit temporarily. In 5.3, we added SMTP authentication failure tracking. To configure: config system security authserver set status [enable, disable, monitor-only] end It uses a variety of adaptive factors, similar to our sender reputation feature to detect and block brute forcing (not just consecutive failures) and temporarily locks out (tarpitting) the user.
Carl
Dr. Carl Windsor Field Chief Technology Officer Fortinet
Hello Carl,
Thank you very much for your response, it's great news! I've just tested it in my lab, and it seams to be working just fine! :)))
However... :) Can you please point me to some documentation or something that would help me understand this feature better? Can I monitor it in the GUI (I already saw the 'diag system authserver scores')? Can I alter the timeout period? Stuff like that, which would help the end customer using this great feature.
Cheers,
Slavko
NSE 7
All oppinions/statements written here are my own.
PCNSE
NSE
StrongSwan
PCNSE
NSE
StrongSwan
To revamp this post: what if I need SMTP authentication for my outside clients (people who are sending email from their mobile devices etc.), and disabling it is not an option?
NSE 7
All oppinions/statements written here are my own.
It is not entirely true that you can't ban IP sources, albeit temporarily. In 5.3, we added SMTP authentication failure tracking. To configure: config system security authserver set status [enable, disable, monitor-only] end It uses a variety of adaptive factors, similar to our sender reputation feature to detect and block brute forcing (not just consecutive failures) and temporarily locks out (tarpitting) the user.
Carl
Dr. Carl Windsor Field Chief Technology Officer Fortinet
Hello Carl,
Thank you very much for your response, it's great news! I've just tested it in my lab, and it seams to be working just fine! :)))
However... :) Can you please point me to some documentation or something that would help me understand this feature better? Can I monitor it in the GUI (I already saw the 'diag system authserver scores')? Can I alter the timeout period? Stuff like that, which would help the end customer using this great feature.
Cheers,
Slavko
NSE 7
All oppinions/statements written here are my own.
I would also like to get more information about this. Anyone know if or where Fortinet has a documentation?
In 5.3, we added SMTP authentication failure tracking.
FWIW; that feature would not be available in a FML100C model.
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.