Anomaly - Fortinet FortiGate FortiGate-60 Administration Manual

Antivirus firewalls version 2.80 mr6
Hide thumbs Also See for FortiGate FortiGate-60:
Table of Contents

Advertisement

Anomaly

Anomaly
298
Caution: Restoring the custom signature list overwrites the existing file.
The FortiGate IPS uses anomaly detection to identify network traffic that does not fit
known or preset traffic patterns. The FortiGate IPS identifies the four statistical
anomaly types for the TCP, UDP, and ICMP protocols.
Flooding
If the number of sessions targeting a single destination in one second is
over a threshold, the destination is experiencing flooding.
Scan
If the number of sessions from a single source in one second is over a
threshold, the source is scanning.
Source session
If the number of concurrent sessions from a single source is over a
threshold, the source session limit is reached.
limit
Destination
If the number of concurrent sessions to a single destination is over a
threshold, the destination session limit is reached.
session limit
You can enable or disable logging for each anomaly, and you can control the IPS
action in response to detecting an anomaly. In many cases you can also configure the
thresholds that the anomaly uses to detect traffic patterns that could represent an
attack.
Note: It is important to know the normal and expected traffic on your network before changing
the default anomaly thresholds. Setting the thresholds too low could cause false positives, and
setting the thresholds too high could miss some attacks.
You can also use the command line interface (CLI) to configure session control based
on source and destination network address. See
page
301.
The anomaly detection list can be updated only when the FortiGate firmware image is
upgraded.
Anomaly list
Figure 150:The Anomaly list
Name
The anomaly names.
Enable
The status of the anomaly. A white check mark in a green circle indicates the
anomaly is enabled. A white X in a grey circle indicates the anomaly is
disabled.
Logging
The logging status for each anomaly. A white check mark in a green circle
indicates logging is enabled for the anomaly. A white X in a grey circle
indicates logging is disabled for the anomaly.
01-28006-0002-20041105
"Anomaly CLI configuration" on
IPS
Fortinet Inc.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents