Configuring Do Not Track / Track and Allow policies
Use to specify IP addresses that FortiDDoS Do Not Track or Track and Allow.
- Do Not Track—Does not monitor or track traffic to or from the configured IP addresses in any way
- Track and Allow—Monitors and reports but does not restrict traffic to/from the configured IP addresses
Use these allow-list policies with extreme care. No mitigation is performed when either of these policies is applied. Avoid using these polices for your protected IP addresses. Do Not Track traffic is completely invisible to FortiDDoS with no monitoring nor mitigation Track and Allow traffic is visible, displaying on graphs and logs with virtual drops (like a mini-Detection Mode) but it may not be obvious from the displayed information that the traffic is not being blocked. |
Before you begin:
- You must have configured address objects that you want to match in policy rules. See Define system ACL objects.
To configure a Do Not Track / Track and Allow policy:
- Go to Global Protection > Do Not Track Policy > IPv4 or IPv6
- Click Create New.
- Complete the configuration as described in the table below.
- Save the configuration.
Settings | Guidelines |
---|---|
Name | Configuration name. a-Z,0-9, - , _ only (no spaces) |
Do Not Track IP Address |
Dropdown menu of IP Addresses, Subnets or IP Ranges previously configured in System > Address and Service. Note: Do Not Track does not support Geolocation, Groups or Services |
Action |
|
Configured policies are shown on the Do Not Track Policy page. You can Edit, Delete, and Clone policies from the GUI using the icons on the right.