Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

block incoming pptp request

Hi, we are having an issue related on pptp attack. the problem is that the firewall is receiving constantly a request for a pptp connection from a specific IP public address. I have tried to create a policy in order to block this ip address but it doesn' t work. Is there any way to block this type of attacks? What can i do? Thanks
8 REPLIES 8
abelio
SuperUser
SuperUser

Your firewall policies are opening 1723/TCP port Close it If you want block an specific IP, put your deny-policy for that IP on top of wan->internal another policies

regards




/ Abel

regards / Abel
Not applicable

It doesn' t work. I' ve tried in all directions. Even from wan to wan, but the firewall doesn' t block this traffic.
abelio

It doesn' t work. I' ve tried in all directions. Even from wan to wan, but the firewall doesn' t block this traffic.
Doesn' t make sense unless you had opened 1723/TCP port to the internet. That' s happens when you enable PPTP within VPN menu (defining incoming firewall policies or not).

regards




/ Abel

regards / Abel
Not applicable

at' s happens when you enable PPTP within VPN menu
Abelio, You mean that I must close 1723TCP from internal->WAN?
abelio

You mean that I must close 1723TCP from internal->WAN?
Not exactly; I mean: if you enable PPTP from VPN menu, you' ll open 1723/TCP port in the FGTbox to accept incoming pptp requests, no matter which firewall policies you' ve configured

regards




/ Abel

regards / Abel
Not applicable

It mean: I can' t allow connect trusted IP, and deny all rest (to pptp service)?
abelio

It mean: I can' t allow connect trusted IP, and deny all rest (to pptp service)?
' Connect' is the keyword; obviously, you can allow only trusted PPTP-users can authenticate against your box; but, once you' ve opened 1723/TCP by enabling PPTP service, you cannot deny TCP-SYN against your WAN interface. I don' t know if I really undertood your question, sorry

regards




/ Abel

regards / Abel
Not applicable

you cannot deny TCP-SYN against your WAN
Thanks
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors