12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring a protection profile<br />

Firewall Protection Profile<br />

IPS options<br />

Figure 217:Protection profile IPS options<br />

The following options are available for IPS through the protection profile.<br />

IPS Signature<br />

IPS Anomaly<br />

Select one or more IPS signature severity levels for this profile. Options<br />

are Critical, High, Medium, Low, and Information. Signatures with severity<br />

levels that have not been selected are not triggered.<br />

Select one or more IPS anomaly severity levels for this profile. Options<br />

are Critical, High, Medium, Low, and Information. Anomalies with severity<br />

levels that have not been selected are not triggered.<br />

Content archive options<br />

See “Intrusion Protection” on page 411 for more IPS configuration options.<br />

You can choose to display the content meta-information of the HTTP, HTTPS,<br />

FTP, IMAP, POP3, SMTP, and IM traffic on the system dashboard, or archive the<br />

full content to a FortiAnalyzer device.<br />

You must enable at least one of the content protection functions, such as AV<br />

scanning, web filtering, and spam filtering, for the relevant protocol, before you<br />

can use the full content archiving features for that protocol. In other words, if no<br />

content protection function is enabled for a protocol, the full content of that<br />

protocol will not be archived to the FortiAnalyzer even if you enable Full Content<br />

Archive.<br />

Taking FTP for example, the following lists the three content archiving scenarios<br />

• If you do not enable AV scanning for FTP, but you select Full Content Archive,<br />

the FTP files will not be archived to the FortiAnalyzer device. Only the metainformation<br />

is recorded.<br />

• If you enable AV scanning for FTP, but you select Pass for files larger than<br />

10MB, files larger than 10MB will not be archived to the FortiAnalyzer device.<br />

Only the meta-information is recorded.<br />

• If you enable AV scanning for FTP, but you select Block for files larger than<br />

10MB, files larger than 10MB will not be archived to the FortiAnalyzer device,<br />

and the meta-information will not be recorded either.<br />

To be able to access all content archiving options, a FortiAnalyzer unit must be<br />

configured and logging to the FortiAnalyzer must be enabled. For more<br />

information, see “Logging to a FortiAnalyzer unit” on page 472.<br />

Figure 218:Protection profile content archive options<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

338 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!