Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MegaSistemas
New Contributor

automatic intrusion ip block

Hello guys

 

I noticed that a certain ip tried to invade a web server and IPS dropped that attempt, but soon after that same ip tried several more times. Is there a way to configure FGT to automatically block this ip for minutes or hours, so you can not keep trying every second? or that it is inserted into a blacklist?

2 Solutions
darwin_FTNT
Staff
Staff

See the following and enable IPS utm profile quarantine feature:

 

https://forum.fortinet.com/tm.aspx?m=151871

 

Quarantine list is maintained by kernel and is more efficient in cpu usage in terms of blocking quarantined client connections.

 

View solution in original post

Bruno_Pereira
New Contributor III

Hello,

 

it's possibilite with quarantine, you can set the time.You can then check the blocked IPs on monitor> quarantine monitor.

 

 

 

 

View solution in original post

2 REPLIES 2
darwin_FTNT
Staff
Staff

See the following and enable IPS utm profile quarantine feature:

 

https://forum.fortinet.com/tm.aspx?m=151871

 

Quarantine list is maintained by kernel and is more efficient in cpu usage in terms of blocking quarantined client connections.

 

Bruno_Pereira
New Contributor III

Hello,

 

it's possibilite with quarantine, you can set the time.You can then check the blocked IPs on monitor> quarantine monitor.

 

 

 

 

Labels
Top Kudoed Authors