Disabling Nids Attack Signatures; Adding User-Defined Signatures - Fortinet FortiGate 50A Installation And Configuration Manual

Fortinet fortigate installation and configuration guide
Hide thumbs Also See for FortiGate 50A:
Table of Contents

Advertisement

Detecting attacks

Disabling NIDS attack signatures

Adding user-defined signatures

218
Figure 32: Example signature group members list
By default, all NIDS attack signatures are enabled. You can use the NIDS signature
list to disable detection of some attacks. Disabling unnecessary NIDS attack
signatures can improve system performance and reduce the number of IDS log
messages and alert emails that the NIDS generates. For example, the NIDS detects a
large number of web server attacks. If you do not provide access to a web server
behind your firewall, you might want to disable all web server attack signatures.
Note: To save your NIDS attack signature settings, Fortinet recommends that you back up your
FortiGate configuration before you update the firmware and restore the saved configuration
after the update.
To disable NIDS attack signatures
1
Go to NIDS > Detection > Signature List.
2
Scroll through the signature list to find the signature group that you want to disable.
Attack ID numbers and rule names in attack log messages and alert email match
those in the signature group members list. You can scroll through a signature group
members list to locate specific attack signatures by ID number and name.
3
Clear the Enable check box.
4
Select OK.
5
Repeat steps
2
to
Select Check All
Select Uncheck All
list.
You can create a user-defined signature list in a text file and upload it from the
management computer to the FortiGate unit.
Note: You cannot upload individual signatures. You must include, in a single text file, all the
user-defined signatures that you want to upload. The file can contain one or more signatures.
For information about how to write user-defined signatures, see the FortiGate NIDS
Guide.
4
for each NIDS attack signature group that you want to disable.
to enable all NIDS attack signature groups in the signature list.
to disable all NIDS attack signature groups in the signature
Network Intrusion Detection System (NIDS)
Fortinet Inc.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents