Custom Signatures; Viewing The Custom Signature List; Creating Custom Signatures - Fortinet FortiGate Series Administration Manual

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

Intrusion Protection

Custom signatures

Viewing the custom signature list

Creating custom signatures

FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903
http://docs.fortinet.com/
Feedback
Custom signatures provide the power and flexibility to customize the FortiGate Intrusion
Protection system for diverse network environments. The FortiGate predefined signatures
represent common attacks. If you use an unusual or specialized application or an
uncommon platform, you can add custom signatures based on the security alerts released
by the application and platform vendors.
You can also create custom signatures to help you block P2P protocols.
After creation, you need to specify custom signatures in IPS sensors created to scan
traffic. For more information about creating IPS sensors, see
page
538.
For more information about custom signatures, see the
Note: If virtual domains are enabled on the FortiGate unit, the Intrusion Protection settings
are configured separately in each VDOM. All sensors and custom signatures will appear
only in the VDOM in which they were created.
To view the custom signature list, go to UTM > Intrusion Protection > Custom.
Figure 315: The custom signature list
Create New
Select to create a new custom signature.
Name
The custom signature name.
Signature
The signature syntax.
Delete and Edit
Delete or edit the custom signature.
icons
Use custom signatures to block or allow specific traffic. For example, to block traffic
containing profanity, add custom signatures similar to the following:
set signature 'F-SBID (--protocol tcp; --flow bi_direction; --
pattern "bad words"; --no_case)'
For more information on custom signature syntax, see the
Note: Custom signatures are an advanced feature. This document assumes the user has
previous experience creating intrusion detection signatures.
Note: Custom signatures must be added to a signature override in an IPS filter to have any
effect. Creating a custom signature is a necessary step, but a custom signature does not
affect traffic simply by being created.
Custom signatures
"Adding an IPS sensor" on
FortiGate UTM User
Guide.
FortiGate UTM User
Guide.
Edit
Delete
535

Advertisement

Table of Contents
loading

Table of Contents