Fortinet Question - IP and Ports being reported to security systems

Started by deanwebb, April 08, 2021, 09:24:55 AM

Previous topic - Next topic

deanwebb

Yo, Wintermute!

We're seeing a situation in which Fortinet firewalls are reporting IP addresses and/or open ports on devices where there's no host at the IP address and no such open port on the device. The common factor is a Fortinet firewall in the path. Is there any setting on the Fortinet that we should check to modify/stop the behavior?
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

wintermute000

can you be more specific about Fortinet firewalls reporting IP addresses / open ports? What exactly is the report or screen or output you're seeing?

deanwebb

This would be reporting via ARP tables and/or responses to NMAP scans.
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

Otanx


wintermute000

I still don't get what its 'reporting'. The FW isn't running NMAP scans or anything like that?
If you mean that when its responding, then yep proxy ARP because theres a VIP or NAT etc.

deanwebb

Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.