Configuring Sniffer Policies - Fortinet FortiGate Series Administration Manual

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

Firewall Policy

Configuring sniffer policies

FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903
http://docs.fortinet.com/
Feedback
Application Black/White
List
Delete icon
Edit icon
Insert Policy Before icon
Move To icon
Use the sniffer policy configuration to specify the interface, a source address, a
destination address, and a service. All of the specified attributes must match network
traffic to trigger the policy.
You can also use the config firewall sinff-interface-policy CLI command
to add sinffer policies from the CLI. For more information, see the
Reference.
You can use the config firewall sniff-interface-policy6 command to add
IPv6 sniffer policies. For more information about FortiGate IPv6 support, see
IPv6 support" on page
289.
Figure 220: Editing a sniffer policy
Source Interface/Zone
Source Address
Destination Address
Service
DoS Sensor
Using one-arm sniffer policies to detect network attacks
The Application Black/White List selected in this policy.
Delete the policy from the list.
Edit the policy.
Add a new policy above the corresponding policy (the New Policy
screen appears).
Move the corresponding policy before or after another policy in the list.
The interface or zone to be monitored.
Select an address, address range, or address group to limit traffic
monitoring to network traffic sent from the specified address or range.
Select Multiple to include multiple addresses or ranges. You can also
select Create New to add a new address or address group.
Select an address, address range, or address group to limit traffic
monitoring to network traffic sent to the specified address or range.
Select Multiple to include multiple addresses or ranges. You can also
select Create New to add a new address or address group.
Select a firewall pre-defined service or a custom service to limit traffic
monitoring to only the selected service or services. You can also
select Create new to add a custom service.
Select and specify a DoS sensor to have the FortiGate unit apply the
sensor to matching network traffic. You can also select Create new to
add a new DoS Sensor. See
FortiGate CLI
"DoS sensors" on page
545.
"FortiGate
409

Advertisement

Table of Contents
loading

Table of Contents