Hi CheckMate.
Customer using customize port for the RDP connection. Which they are using port 33389 instead of 3389, I was not sure what the reason for them to do the changes.
And recently they found the RDP brute force that detect on they internal Fortigate FW. But Checkpoint was doesn't detect any IPS log. So I was suggested them to sync the condition that using to trigger the prevention. Kindly refer the protection i was suggested them to customized.
So here my question, did IPS protection able to trigger for the blocking action even the custom port was using for the RDP traffic? Or due to the custom port change for RDP connection will cause the protection won't be trigger at all?
Really appreciate if got any idea can share regard this.
Attach screenshot for the protection suggest customer to override action with "Prevention" and the customized condition suggest to be align with Fortigate.
Thanks and regard,
Woon