Ips - Fortinet FortiGate FortiGate-200A Administration Manual

Fortinet fortigate fortigate-200a: user guide
Hide thumbs Also See for FortiGate FortiGate-200A:
Table of Contents

Advertisement

IPS

FortiGate-200A Administration Guide
FortiGate-200A Administration Guide Version 2.80 MR6
The FortiGate Intrusion Prevention System (IPS) combines signature- and anomaly-
based intrusion detection and prevention with low latency and excellent reliability. The
FortiGate unit can record suspicious traffic in logs, can send alert email to system
administrators, and can log, pass, drop, reset, or clear suspicious packets or
sessions. You can adjust some IPS anomaly thresholds to work best with the normal
traffic on the protected networks. You can also create custom signatures to customize
the FortiGate IPS for diverse network environments.
You can configure the IPS globally and then enable or disable all signatures or all
anomalies in individual firewall protection profiles.
and where to configure and access them. To access protection profile IPS options go
to Firewall > Protection Profile, select edit or Create New, and select IPS. See
"Protection profile options" on page
Table 23: IPS and Protection Profile IPS configuration
Protection Profile IPS options
IPS Signature
Enable or disable IPS signatures for all
network services.
IPS Anomaly
Enable or disable IPS anomalies for all
network services.
Protection profile configuration
For information about adding protection profiles to firewall policies, see
protection profile to a policy" on page
IPS updates and information
FortiProtect services are a valuable customer resource and include automatic updates
of virus and IPS (attack) engines and definitions through the FortiProtect Distribution
Network (FDN). The FortiProtect Center also provides the FortiProtect virus and
attack encyclopedia and the FortiProtect Bulletin.
Visit the FortiProtect Center at http://www.fortinet.com/FortiProtectCenter/.
To set up automatic and push updates see
01-28006-0072-20041105
Table 23
225.
IPS setting
IPS > Signature
View and configure a list of predefined
signatures.
Create custom signatures based on the
network requirements.
IPS > Anomaly
View and configure a list of predefined
anomalies.
230.
"Update center" on page
describes the IPS settings
"To add a
120.
293

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents