Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
balaji
New Contributor

Unknown hits in Local Traffic

Dear Team, In Log & Report - Traffic Log - Local Traffic - almost 9 lakh unknown ip address try to hit my fortigate box. How do i rescue firewall and webserver... Do needful....
4 REPLIES 4
dasilva13
New Contributor

I am a little confused... what do you mean rescue your FortiGate box? do you want to block these IP addresses?
balaji

Yes i want to block all unknown ip address. I gave a strong password to that device any possible to hack that password. Because they hit 1000 times in a minute
rwpatterson
Valued Contributor III

Turn off outside access to the protocol they are hitting with. HTTP (God I hope not), HTTPS, SSH, (better not be TELNET!), etc. Management ideally should only be from a secure interface. Most of us agree that any management should only be done after a VPN into the unit first. More work, but more secure.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
hklb
Contributor II

Hello, You want to block access to your firewall administration ? or access to your webserver ? for firewall adminsitration, your can restrict admin access by configuring permited IP on the admin user. If it is for your web server(or other server), you can do that with a firewall rules allowing some IP to access to your VIP, or by configuring DDOS policy (depending of your firewall model) : http://docs-legacy.fortinet.com/fos50hlp/52/index.html#page/FortiOS%25205.2%2520Help/protection_chapter.076.25.html
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors