Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ritterm
New Contributor

Threat actors constantly trying to log into the Firewall

Hey folks,

 

My logs have been getting filled up for a long time. We have email-based two-factor authentication on but this situation still scares me. Our Firewall is accessible from the external IP and it seems folks are trying to use ssh. What should I tell you about what I see from the logs and what can I do to remedy this?

5 REPLIES 5
akanibek
Staff
Staff

Hi @ritterm ,

do you need access outside to your firewall? If yes, then I would suggest to:

1) Make admin accounts password stronger.

2) Optionally disable admin account, and create another super admin account with 2FA;

3) Change the default SSH port to another, as well as HTTPS GUI;

4) Optionally configure trusted hosts;

5) Provide access to FGT from terminal server, jumphost inside your local network.  

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-System-administrator-best-practices/ta-p/1...

Asset
ede_pfau
SuperUser
SuperUser

Opening an edge firewall's admin ports to the internet is a no-go!

If you want to manage the FGT remotely, create a dial-up IPsec VPN. If really needed, you could restrict access from limited IP range, or country, via Local-In policy.


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
BusinessUser

how do you restrict access from country or local in policy?

ebilcari

You have to create an address object Type Geography and select the country like described here. Than from CLI you can use this as a source for a local in policy:

config firewall local-in-policy
edit 1
set srcaddr "Atlas_IP"
- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
mgoswami
Staff
Staff

Hi,

 

You may restrict HTTPS access to your Fortigate to specific country by referring to the below KB:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Restrict-HTTPS-access-from-certain-countri...

BR,

Manosh

Labels
Top Kudoed Authors