12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Intrusion Protection<br />

About intrusion protection<br />

Intrusion Protection<br />

The <strong>FortiGate</strong> Intrusion Prevention System (IPS) <strong>com</strong>bines signature and<br />

anomaly intrusion detection and prevention with low latency and excellent<br />

reliability. IPS provides configuration access to the IPS options enabled when<br />

creating a firewall protection profile.<br />

This section describes how to configure the <strong>FortiGate</strong> IPS settings. For detailed<br />

information about IPS, see the <strong>FortiGate</strong> Intrusion Protection System (IPS) <strong>Guide</strong>.<br />

This section describes:<br />

• About intrusion protection<br />

• Predefined signatures<br />

• Custom signatures<br />

• Protocol Decoders<br />

• Anomalies<br />

• IPS CLI configuration<br />

About intrusion protection<br />

The <strong>FortiGate</strong> unit can record suspicious traffic in logs, can send alert email to<br />

system administrators, and can log, pass, drop, reset, or clear suspicious packets<br />

or sessions. Adjust some IPS anomaly thresholds to work best with the normal<br />

traffic on the protected networks. Create custom signatures to customize the<br />

<strong>FortiGate</strong> IPS for diverse network environments.<br />

The <strong>FortiGate</strong> IPS matches network traffic against patterns contained in attack<br />

signatures. Attack signatures reliably protect your network from known attacks.<br />

Fortinet’s FortiGuard infrastructure ensures the rapid identification of new threats<br />

and the development of new attack signatures.<br />

FortiGuard services are a valuable customer resource and include automatic<br />

updates of virus and IPS (attack) engines and definitions through the FortiGuard<br />

Distribution Network (FDN). The FortiGuard Center also provides the FortiGuard<br />

virus and attack encyclopedia and the FortiGuard Bulletin. Visit the Fortinet<br />

Knowledge Center for details and a link to the FortiGuard Center.<br />

The connection between the <strong>FortiGate</strong> unit and FortiGuard is configured in<br />

System > Maintenance > FortiGuard Center. See “Configuring the <strong>FortiGate</strong><br />

unit for FDN and FortiGuard services” on page 188 for more information.<br />

Configure the <strong>FortiGate</strong> unit to check automatically for and download updated<br />

attack definition files containing the latest signatures, or download the updated<br />

attack definition file manually. Alternately, configure the <strong>FortiGate</strong> unit to allow<br />

push updates of updated attack definition files as soon as they are available from<br />

the FortiGuard Distribution Network.<br />

When the <strong>FortiGate</strong> unit installs an updated attack definition file, it checks to see if<br />

the default configuration for any existing signatures has changed. If the default<br />

configuration has changed, the changes are preserved.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 411

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!