Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IP reputation log entry?
Testing IP reputation filtering on a FortiGate 2200E, I managed to get it working alright. My finding being, that packets that didn't meet the specified reputation level will fall through and hit the implicit deny or, in case of, a lower level explicit deny rule (instead of a direct drop).
The only thing I find missing, is a simple log entry indicating that IP reputation has been triggered. Does anyone know if an IP reputation trigger even produces a log entry? Any help is much appreciated!
Labels:
- Labels:
-
FortiGate
1 REPLY 1
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You should see a dstreputation field in the traffic logs.
Cheers,
Graham
Graham
