Configuring Ips Logging And Alert Email; Default Fail Open Setting - Fortinet FortiGate FortiGate-4000 Administration Manual

Fortinet fortigate fortigate-4000: user guide
Hide thumbs Also See for FortiGate FortiGate-4000:
Table of Contents

Advertisement

Configuring IPS logging and alert email

Configuring IPS logging and alert email

Default fail open setting

302
Whenever the IPS detects or prevents an attack, it generates an attack message. You
can configure the FortiGate unit to add the message to the attack log and to send an
alert email to administrators. You can configure how often the FortiGate unit sends
alert email. You can also reduce the number of log messages and alerts by disabling
signatures for attacks that your system is not vulnerable to (for example, web attacks
when you are not running a web server). For more information on FortiGate logging
and alert email, see
"Log & Report" on page
If for any reason the IPS should cease to function, it will fail open by default. This
means that crucial network traffic will not be blocked and the Firewall will continue to
operate while the problem is resolved.
You can change the default fail open setting using the CLI:
config sys global
set ips-open [enable | disable]
end
Enable ips_open to cause the IPS to fail open and disable ips_open to cause the
IPS to fail closed.
01-28006-0012-20041105
349.
IPS
Fortinet Inc.

Advertisement

Table of Contents
loading

Table of Contents