IPS
Signature
FortiGate-1000A/FA2 Administration Guide
01-28011-0254-20051115
299
Custom signatures provide the power and flexibility to customize the FortiGate IPS for
diverse network environments. The FortiGate predefined signatures cover common
attacks. If you are using an unusual or specialized application or an uncommon
platform, you can add custom signatures based on the security alerts released by the
application and platform vendors.
You can also use custom signatures to block or allow specific traffic. For example to
block traffic containing pornography, you can add custom signatures similar to the
following:
F-SBID (--protocol tcp; --flow established; --content "nude cheerleader"; --no_case)
When you add the signature set action to Drop Session.
For more information on custom signature syntax see the
FortiGate IPS Custom
Signatures Technical Bulletin
.
Custom signature list
Figure 154:The custom signature group
Note:
Custom signatures are an advanced feature. This document assumes the user has
previous experience creating intrusion detection signatures.
Enable custom
signature
Select the Enable custom signature box to enable the custom signature
group or clear the Enable custom signature box to disable the custom
signature group.
Create New
Select Create New to create a new custom signature.
Clear all custom
signatures
Remove all the custom signatures from the custom signature group.
Reset to
recommended
settings?
Reset all the custom signatures to the recommended settings.
Name
The custom signature names.
Revision
The revision number for each custom signature. The revision number is a
number you assign to the signature when you create or revise it.
Enable
The status of each custom signature. A white check mark in a green circle
indicates the signature is enabled. A white X in a grey circle indicates the
signature is disabled.
Selecting the box at the top of the Enable column enables all the custom
signatures. Clearing the box at the top of the Enable column disables all the
custom signatures.
Logging
The logging status of each custom signature. A white check mark in a green
circle indicates logging is enabled for the custom signature. A white X in a
grey circle indicates logging is disabled for the custom signature.
Action
The action set for each custom signature. Action can be Pass, Drop, Reset,
Reset Client, Reset Server, Drop Session, Clear Session, or Pass Session.
Modify
The Delete and Edit/View icons.
Summary of Contents for FortiGate 1000A
Page 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Page 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Page 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Page 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Page 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Page 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Page 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...