Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tester00131
New Contributor

Can't RDP to server after enable IPS Profile

I want to protect my server from RDP Brute forces but after enable Security Profiles. I can't access to server anymore.

 

2 REPLIES 2
Yurisk
Valued Contributor

- Without looking at your policy & Security Profile impossible to say what might have happened.

- Fortigate does not proxy RDP connections so it will not differentiate between successful/failed RDP login attempts to block the brute force flood. 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
tester00131

My config is

#####

config firewall policy edit 5 set name "NATING_to_WEBs1" set uuid **** set srcintf "VLAN 401" set dstintf "VLAN 410" set srcaddr "y.y.y.y" set dstaddr "WEBs1toINTERNET" # this object is NAT public : 180.1x.x.x to private 192.168.1.10 set action accept set schedule "always" set service "ALL" set utm-status enable set ips-sensor "default" set logtraffic all next end

#####

 

IF I try to RDP to 180.1x.x.x  when enable ips-sensor, result is fail. 

IF I try to RDP to 180.1x.x.x  when disable ips-sensor, result is success. 

Labels
Top Kudoed Authors