What is the question?
Looking at the log entry, it looks like you've got a private IP to private IP (meaning IPs within subnets that are only supposed to be used for private networks) broadcast of Netbios NS, which is getting denied by your default deny security policy, meaning you don't have an explicit security policy to allow or deny it.
The thing that is off is that this is coming in your wan1 interface. Assuming your wan1 interface is actually connected to the wan you shouldn't be getting netbios from there, since it is a non-routable protocol.
More information on your config, situation, and what your actual question is would be helpful.
If you're also getting this from 169.254.x.x then its likely some device that hasn't yet got its own IP through DHCP.
Is wan1 a static IP? Does it have any secondary IP Addresses set? What's directly connected to the wan1 port? If it's a cable modem or similar, what is its local (not public) IP? And is anything else plugged into that modem/device?
I've seen one similar issue (DHCP and netbios on a wan port) with a messed up multi-tenant configuration provided by an ISP.
I'm assuming/hoping you don't have wan1 or wan2 set as DHCP servers? Just to be sure, you should probably check what DHCP clients the FortiGate does have (Monitor, DHCP Monitor).
Can you deny 137/UDP outbound (LAN-192.168.x.x -> WAN)? Then provide di sniffer packet wan1 "port 137" 4 10 l
I guess I hit the send button too early. I suspect Proxy Arp inspection. Please, provide the output of show system proxy-arp.
Thanks
Do you have the following configuration forwarding NetBIOS request to WINS server on the internal interface ?
config system interfaceedit internalset netbios_forward enableset wins-ip x.x.x.xendSelect Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.