Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dave2318
New Contributor

View IPS Quarantined IP's and why doesn't block work?

Hi All,

 

We have 2 x Fortigate 300C's in Active/Passive running 5.2.4.

 

We are currently being battered by thousands of SQL injection attempts. Most seem to be being blocked by the IPS rules I have set, but our webserver log IS showing SQL injection attempts! Any idea why?

 

For now I have changed the "Block ALL" option to "Quarantine for 1 hour" and that seems to have stopped it for a bit!

How do I view a list of quarantined IP's?

 

Thanks in advance.

 

Dave

2 REPLIES 2
razor
New Contributor III

I have the same Q. Maybe there is a fortinet tech guy who is able to answer this question? :)

Fortinet Network Security Professional (NSE4)

Fortinet Network Security Professional (NSE4)
Ralph1973

Hi, do you have configured the

- correct ips sensor

- put that sensor in the policy that is used?

 

Is the traffic coming from the internet or from the inside (also possible)

Configure the extended ips database (temporarily)

config ips global     set database extended

 

and make sure that the sensor has all signatures needed

 

Hope this helps

p.s. the quarantined ip's are listed under user, monitor

 

Kind regards,

Ralph Willemsen

Arnhem, Netherlands

Labels
Top Kudoed Authors