FortiGate-5000 series Administration Guide Version 2.80 MR8
FortiGate-5000 series Administration Guide
01-28008-0013-20050204
285
IPS
The FortiGate Intrusion Prevention System (IPS) combines signature and anomaly
intrusion detection and prevention with low latency and excellent reliability. The
FortiGate unit can record suspicious traffic in logs, can send alert email to system
administrators, and can log, pass, drop, reset, or clear suspicious packets or
sessions. You can adjust some IPS anomaly thresholds to work best with the normal
traffic on the protected networks. You can also create custom signatures to customize
the FortiGate IPS for diverse network environments.
You can configure the IPS globally and then enable or disable all signatures or all
anomalies in individual firewall protection profiles.
Table 26
describes the IPS settings
and where to configure and access them. To access protection profile IPS options go
to Firewall > Protection Profile, select edit or Create New, and select IPS. See
“Protection profile options” on page 234
.
Protection profile configuration
For information about adding protection profiles to firewall policies, see
“To add a
protection profile to a policy” on page 239
.
IPS updates and information
FortiProtect services are a valuable customer resource and include automatic updates
of virus and IPS (attack) engines and definitions through the FortiProtect Distribution
Network (FDN). The FortiProtect Center also provides the FortiProtect virus and
attack encyclopedia and the FortiProtect Bulletin.
Visit the FortiProtect Center at
http://www.fortinet.com/FortiProtectCenter/
.
To set up automatic and push updates see
“Update center” on page 128
.
Table 26: IPS and Protection Profile IPS configuration
Protection Profile IPS options
IPS setting
IPS Signature
IPS > Signature
Enable or disable IPS signatures for all
network services.
View and configure a list of predefined
signatures.
Create custom signatures based on the
network requirements.
IPS Anomaly
IPS > Anomaly
Enable or disable IPS anomalies for all
network services.
View and configure a list of predefined
anomalies.
Summary of Contents for FortiGate FortiGate-5020
Page 86: ...86 01 28008 0013 20050204 Fortinet Inc Dynamic IP System DHCP ...
Page 118: ...118 01 28008 0013 20050204 Fortinet Inc FortiManager System Config ...
Page 254: ...254 01 28008 0013 20050204 Fortinet Inc CLI configuration User ...
Page 318: ...318 01 28008 0013 20050204 Fortinet Inc CLI configuration Antivirus ...
Page 350: ...350 01 28008 0013 20050204 Fortinet Inc Using Perl regular expressions Spam filter ...
Page 370: ...370 01 28008 0013 20050204 Fortinet Inc CLI configuration Log Report ...
Page 382: ...382 01 28008 0013 20050204 Fortinet Inc Glossary ...
Page 402: ...402 01 28008 0013 20050204 Fortinet Inc Index ...