Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gmuzio
New Contributor

Fortigate 1200D and heavy DDoS

Hello,

 

I've a Fortigate 1200D unit as a firewall for mitigating DDoS attacks. But I'm having issues with some kind of DDoS attacks. 

For example, with attacks with heavy pps count (arround 2 millons of packets per second). 

When I receive an attack of these characteristics, the CPU of the Fortigate rises only to 60/70% (never to 100%), the sessions are increased up to 800k and upon reaching this amount, the team begins to close stabilized and legitimate sessions. An example of this is that all the BGP sessions established in the interface where the attack enters are closed because the holdtime expires.

I understand that this equipment should work perfectly for this type of DDoS attacks. In the specifications it says that it can reach 11 million concurrent sessions and 72 million packages per second. Under normal conditions the device manages 2 Gbps of traffic at peak and around 200k sessions.

 

I think I have a problem with the configuration.

 

Im using firmware v5.2.10,build742 (GA). 

 

If someone can help me with this, I would appreciate it very much.

 

Regards

0 REPLIES 0
Labels
Top Kudoed Authors