- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
automatic intrusion ip block
Hello guys
I noticed that a certain ip tried to invade a web server and IPS dropped that attempt, but soon after that same ip tried several more times. Is there a way to configure FGT to automatically block this ip for minutes or hours, so you can not keep trying every second? or that it is inserted into a blacklist?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See the following and enable IPS utm profile quarantine feature:
https://forum.fortinet.com/tm.aspx?m=151871
Quarantine list is maintained by kernel and is more efficient in cpu usage in terms of blocking quarantined client connections.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
it's possibilite with quarantine, you can set the time.You can then check the blocked IPs on monitor> quarantine monitor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See the following and enable IPS utm profile quarantine feature:
https://forum.fortinet.com/tm.aspx?m=151871
Quarantine list is maintained by kernel and is more efficient in cpu usage in terms of blocking quarantined client connections.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
it's possibilite with quarantine, you can set the time.You can then check the blocked IPs on monitor> quarantine monitor.