- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SMTP Auth Failure?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is not entirely true that you can't ban IP sources, albeit temporarily. In 5.3, we added SMTP authentication failure tracking. To configure: config system security authserver set status [enable, disable, monitor-only] end It uses a variety of adaptive factors, similar to our sender reputation feature to detect and block brute forcing (not just consecutive failures) and temporarily locks out (tarpitting) the user.
Carl
Dr. Carl Windsor
Chief Information Security Officer (CISO)
Fortinet
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Carl,
Thank you very much for your response, it's great news! I've just tested it in my lab, and it seams to be working just fine! :)))
However... :) Can you please point me to some documentation or something that would help me understand this feature better? Can I monitor it in the GUI (I already saw the 'diag system authserver scores')? Can I alter the timeout period? Stuff like that, which would help the end customer using this great feature.
Cheers,
Slavko
NSE 7
All oppinions/statements written here are my own.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To revamp this post: what if I need SMTP authentication for my outside clients (people who are sending email from their mobile devices etc.), and disabling it is not an option?
NSE 7
All oppinions/statements written here are my own.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is not entirely true that you can't ban IP sources, albeit temporarily. In 5.3, we added SMTP authentication failure tracking. To configure: config system security authserver set status [enable, disable, monitor-only] end It uses a variety of adaptive factors, similar to our sender reputation feature to detect and block brute forcing (not just consecutive failures) and temporarily locks out (tarpitting) the user.
Carl
Dr. Carl Windsor
Chief Information Security Officer (CISO)
Fortinet
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Carl,
Thank you very much for your response, it's great news! I've just tested it in my lab, and it seams to be working just fine! :)))
However... :) Can you please point me to some documentation or something that would help me understand this feature better? Can I monitor it in the GUI (I already saw the 'diag system authserver scores')? Can I alter the timeout period? Stuff like that, which would help the end customer using this great feature.
Cheers,
Slavko
NSE 7
All oppinions/statements written here are my own.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would also like to get more information about this. Anyone know if or where Fortinet has a documentation?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In 5.3, we added SMTP authentication failure tracking.
FWIW; that feature would not be available in a FML100C model.
PCNSE
NSE
StrongSwan
