Network Intrusion Detection System (Nids); Detecting Attacks - Fortinet FortiGate 50A Installation And Configuration Manual

Fortinet fortigate installation and configuration guide
Hide thumbs Also See for FortiGate 50A:
Table of Contents

Advertisement

FortiGate-50A Installation and Configuration Guide Version 2.50
Network Intrusion Detection System
(NIDS)

Detecting attacks

FortiGate-50A Installation and Configuration Guide
The FortiGate NIDS is a real-time network intrusion detection sensor that uses attack
signature definitions to both detect and prevent a wide variety of suspicious network
traffic and direct network-based attacks. Also, whenever an attack occurs, the
FortiGate NIDS can record the event in a log and send an alert email to the system
administrator.
This chapter describes:
Detecting attacks
Preventing attacks
Logging attacks
The NIDS Detection module detects a wide variety of suspicious network traffic and
network-based attacks. Use the following procedures to configure the general NIDS
settings and the NIDS Detection module Signature List.
For the general NIDS settings, you must select which interfaces you want to be
monitored for network-based attacks. You also need to decide whether to enable
checksum verification. Checksum verification tests the integrity of packets received at
the monitored interfaces.
This section describes:
Selecting the interfaces to monitor
Disabling monitoring interfaces
Configuring checksum verification
Viewing the signature list
Viewing attack descriptions
Disabling NIDS attack signatures
Adding user-defined signatures
215

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents