Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tbryant
New Contributor

Digital Ocean - Droplets

Has anyone dealt with the "droplets" from Digital Ocean? I am seeing a bunch of VPN traffic to them, ISAKMP. Trying to figure out the best way to block that traffic on our network.

 

Thanks!

3 REPLIES 3
hmtay_FTNT
Staff
Staff

Hello tbryant,

 

If you are okay blocking ISAKMP traffic in your network, you could use the Application Control signature, "ISAKMP" to block those traffic.

MikePruett

I have used droplets before as a developer. Made it easy to stand up a VM, test some app stuff etc.

 

The people may be building tunnels so their droplets aren't publicly accessible. Block it and see who comes screaming (as long as you have the approval of your leadership/change management of course)

Mike Pruett Fortinet GURU | Fortinet Training Videos
emnoc
Esteemed Contributor III

Same here, I've used Digital Ocean dev and POCs and we do just this for droplets. Do you have any particular reason for disallowing ISAKMP?

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors