- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DoS-Banned-IP
Hello, I've got question about Denial policy in Fortigate. I put set up for DoS on my Wan IP with test thresholds like some examples below;
config anomaly edit "icmp_flood" set status enable set log enable set action block set quarantine attacker set quarantine-expiry 15m set quarantine-log enable set threshold 100
Now when I put some nmap scan from outside network to my WAN IP I get banned my IP address is putted on quaranteen list but even tough I can still ping WAN IP and I don't know why ?
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So this is all normal behaviour. A banned-ip (quarantine) will still be able to ping the FW WAN interface. As metnioned in the doc I posted earlier, "The banned user list is kept in the kernel, and used by Antivirus, Data Leak Prevention (DLP), DoS, and Intrusion Prevention System (IPS). Any policies that use any of these features will block traffic from the attacker's IP address."
Pinging the WAN IP does not involve any FW policies (it is local-in traffic).
The DDOS profile will continue to block ICMP floods, however.
Graham
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fairly certain quarantined IP addresses are only checked in firewall policies which are only checked in forwarded traffic not local-in traffic.
https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/771644/dos-policy#Quaranti
Graham
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I get confused because in tutorials on Youtube with the same config when someone put flood icmp on WAN IP from outside get blocked and in my not.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does that tutorial show it getting blocked on the WAN interface or on a FW policy? Can you share the tutorial?
Graham
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
https://www.youtube.com/watch?v=bGffZFPM5rU&ab_channel=EwakoNetwork
This one when he start attack it get banned and flood is stopped.
In my case I get banned IP from external network but even tough I still can ping.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So this is all normal behaviour. A banned-ip (quarantine) will still be able to ping the FW WAN interface. As metnioned in the doc I posted earlier, "The banned user list is kept in the kernel, and used by Antivirus, Data Leak Prevention (DLP), DoS, and Intrusion Prevention System (IPS). Any policies that use any of these features will block traffic from the attacker's IP address."
Pinging the WAN IP does not involve any FW policies (it is local-in traffic).
The DDOS profile will continue to block ICMP floods, however.
Graham
