Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
WaveDev
New Contributor

Separate anti DDoS quarantines

Hi,
I'm using FotiOS 7.0.14

Behind my Fortigate cluster i have running multimple web services with separate public IPs.
When DOS threshlds are triggered Fortigate starts blocking source IPs including those that belongs to our Pingdom monitoring.
Since quarantine is global it also influence other applications.
Is there a way to configure quarantines per project or public IP?

 

1 Solution
Yurisk
SuperUser
SuperUser

Hi, 

nope, there is no such option. But you do have option of creating DDOS policy per source/destination IP - you could create as top most the specific DDOS rules for Pingdom servers IP to basically exempt them from DDOS policy. 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.

View solution in original post

Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
3 REPLIES 3
Yurisk
SuperUser
SuperUser

Hi, 

nope, there is no such option. But you do have option of creating DDOS policy per source/destination IP - you could create as top most the specific DDOS rules for Pingdom servers IP to basically exempt them from DDOS policy. 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
WaveDev
New Contributor

For Pingdom it will not work since they are using some cloud solution for it's uptime checks, and IPs are constantly changing.
Any way, thanks i'we get information that i needed.

AEK
SuperUser
SuperUser

Just a detail.. FG can do anti-DoS, not anti-DDoS.

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors