Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kinmun
New Contributor II

traceroute intrusion detected

i have some windows 10 client getting the following traceroute intrusion.

what should i do ?

or i can just ignore them since the threat level is low.

destination is some site in microsoft.com

 

3 REPLIES 3
kinmun
New Contributor II

how do i prevent/block these 2 clients from doing the traceroute/icmp "attacks" ?

i have already create a rule to block traceroute and icmp for these 2 clients.

 

kinmun
New Contributor II

its says related to CVE-1999-0525.

traceroute packet.

is it really harmless 

 

kurtli_FTNT

Hi there, 

   According to the fortiguard/IPS, this is a low level problem. So if you've setup a rule on FGT to block these 2 PCs traceroute, then this information gathering stopped. If this problem happens constantly, for the root cause, you probably need to dig into these two windows to find out which process/daemon or even malware is sending out this probe.  Suggest to download a forticlient to scan the entire computer to see if anything wrong.

 

 

Thanks

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors