Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fsmar
New Contributor

IP.Unknown.Option

Hi all

 

I'm getting the following, I am aware also what is causing it (a known internal security scan), how can i DISABLE getting notified about these  "IP.Unknown.Option" alerts?  can someone point me to the right cli commands (or gui settings) Its a fg200b running 5.2.13

 

Message meets Alert condition
The following intrusion was observed: IP.Unknown.Option.
date=2020-07-25 time=21:38:55 devname=XXXXXX devid=XXXXXX logid=0720018432 type=anomaly subtype=anomaly level=alert vd="root" severity=critical srcip=XXXXXX srccountry="Reserved" dstip=XXXXXX srcintf="XXXXXX" sessionid=0 action=dropped proto=6 service=HTTP count=2 attack="IP.Unknown.Option" srcport=33753 dstport=80 attackid=108 ref="http://www.fortinet.com/ids/VID108" msg="anomaly: IP.Unknown.Option, repeats 2 times" crscore=50 crlevel=critical

 

 

3 REPLIES 3
fsmar
New Contributor

i tried this but didnt work (from another website)

config ips sensor
     edit "IP.Unknown.Option"
         config entries
             edit 1
                set rule 180
                set log disable
             next
         end
     next
 end

darwin_FTNT

Hi fsmar,

Can check the following docs:

https://kb.fortinet.com/kb/documentLink.do?externalID=FD33609

 

 

fsmar

darwin wrote:

Hi fsmar,

Can check the following docs:

https://kb.fortinet.com/kb/documentLink.do?externalID=FD33609

 

 

 

I dont think it is the same case, can you tell me more about it? I dont see there any documentation on how to disable these notifications

Labels
Top Kudoed Authors