FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kjiye
Staff
Staff
Article Id 261859
Description This article describes how to set up DoS policy exceptions.
Scope FortiGate.
Solution

Like Firewall policy, DoS policy works top-down.

Therefore, if a policy for a specific IP and service to which the DoS policy is not applied is created at the top, an exception is processed.

 

Example:

 

  1. There are two DoS policies.

 

 

z.PNG

 

     2. The policyid 2 was set to block all packets when a DoS attack occurs on the source IP 10.0.1.0/24.

 

policy2.PNG 

     3. Policy3 was created to enable communication only for HTTP and DNS services of 10.0.1.10 IP.

The action was arbitrarily selected as 'Disabled'.

 

policy3.PNG

 

     4. Result in 10.0.1.10 PC.

 

The HTTPS site (https://google.com) failed to access, and the HTTP site (http://httpbin.org) succeeded.

 

accessable.PNG

fail.PNG