We're blocking good traffic because we set up the tcp_port_scan filter. The traffic is coming in on http/https. What is the Fortinet definition of the word "scan"?
IBM defines it as "probing each port for a response.", whereas Fortinet defines a tcp_port_scan as an excessive 'rate of TCP packet from an IP address...'. Wouldn't excessive traffic be monitored by tcp_src_session?
Thanks!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
These look like FortiGate CLI instructions. You might get more responses on that Forum.
Generally tcp_src_sessions is looking at the number of connections a particular source is starting/maintaining.
You are correct that normally a "scan" is a probe (vertical for ports, horizontal for IP addresses) but in this case FortiGate uses this to indicate a pps rate per TCP port. Port rate limiting is usually a last-resort situation and these should be set pretty high.
Thanks for conforming the strange labeling Steve. I'll ramp up the numbers on those blocks.
I don't see a CLI forum. What's it called?
Sorry, I was not referring to a CLI forum but to the FortiGate Forums. FortiDDoS (this forum) is a completely different product line for DDoS mitigation only. The CLI commands you are using come from FortiGate, not FortiDDoS. I am not a FortiGate expert and expect you would get better responses from the people who monitor the FortiGate forums.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.