Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
buddyd
New Contributor

dropped vs detected

Hi Folks, We have a pair of FG 240D' s sitting behind our ASA. These were config' d by a vendor so they are a black box to us, looking for what should be to the forum some simple answers. The vendor setup an outside VDOM with DoS policies. For most attacks, we are seeing a status of dropped which I' m told means blocked. For anomalies, we get a status of detected, which is making management question the configuration. What is the difference between dropped and detected? Is " detected" a problem that is not dealt with? Many thanks in advance. buddyd
3 REPLIES 3
Baptiste
Contributor II

Hi, I guess : Dropped : paquets are dropped Detected : no action, just log

2 FGT 100D  + FTK200

3 FGT 60E  FAZ VM  some FAP 210B/221C/223C/321C/421E

2 FGT 100D + FTK200 3 FGT 60E FAZ VM some FAP 210B/221C/223C/321C/421E
buddyd
New Contributor

Thanks for the quick reply, Baptiste! Yeah, got a response from the vendor (finally) and he agreed the profile(s) should be modified to block, which has been done.
Dipen
New Contributor III

Hi Initially go for the signature defaults, let it run for a couple of months then customize. This is to minimize false positives. Regards

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors