Re: Fortigate 60E - "connection refused" for incoming traffic to VIP ports
Hi emnoc, thanks for the quick reply.
Do you think that message could come from the mail server instead? I have trouble checking there because the software has been somewhat damaged in the last few months, showing few / truncated logs, and we didn't fix it because we are moving the service to the Cloud in the next weeks. But, I could check the historical logs on disk, they could be more complete.
UPDATE: looks like you hit the target.
I have a bunch of "dynamic screening" messages in the disk logs, citing the firewall as the source... dynamic screening blocks for 30 minutes any "curious" traffic, but it never blocks internal (private) IPs.. they are all excluded by default.
... except, this customer used public IPs for his internal LAN! So the LAN-side IP of the firewall was blocked for 30 minutes at a time...
RESOLVED - THANKS A LOT! :)