Configuring message flood detection
To have the Carrier-enabled FortiGate unit check for message floods, you must first configure the flood threshold in an MMS profile, select the MMS profile in a security policy. All the traffic examined by the security policy will be checked for message floods according to the threshold values you set in the MMS profile.
Configure the MMS profile – web-based manager
- Go to Firewall Objects > MMS Profile.
- If you are editing an MMS profile, select the Edit icon of the MMS profile.
If you are creating a new MMS profile, select Create New and enter a profile name.
- Expand MMS Bulk Email Filtering Detection.
- Expand Message Flood.
- Expand Flood Threshold 1.
- Select the Enable check box for MM1 messages, MM4 messages, or both.
- In the Message Flood Window field, enter the length of time the Carrier-enabled FortiGate unit will keep track of the number of messages each subscriber sends.
If the Carrier-enabled FortiGate unit detects the quantity of messages specified in the Message Flood Limit sent during the number of minutes specified in the Message Flood Window, a message flood is in progress.
- In the Message Flood Limit field, enter the number of messages required to trigger the flood.
- In the Message Flood Block Time field, enter the length of time a user will be blocked from sending messages after causing the message flood.
- Select the message flood actions the Carrier-enabled FortiGate unit will take when the message flood is detected.
- Select OK.
Configure the security policy – web-based manager
- Go to Policy.
- Select the Edit icon of the security policy that controls the traffic in which you want to detect message floods.
- Select the MMS Profile check box to enable the use of a protection profile.
- Select the MMS protection profile from the list.
- Select OK.
