12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

About intrusion protection<br />

Intrusion Protection<br />

IPS settings and controls<br />

Create custom attack signatures for the <strong>FortiGate</strong> unit to use in addition to an<br />

extensive list of predefined attack signatures.<br />

Whenever the IPS detects or prevents an attack, it generates an attack message.<br />

Configure the <strong>FortiGate</strong> unit to add the message to the attack log and send an<br />

alert email to administrators. Configure how often the <strong>FortiGate</strong> unit sends alert<br />

email. Reduce the number of log messages and alerts by disabling signatures for<br />

attacks to which the system is not vulnerable, for example, web attacks when<br />

there is no web server running.<br />

Packet logging provides administrators with the ability to analyze packets for<br />

forensics and false positive detection.<br />

For more information about <strong>FortiGate</strong> logging and alert email, see “Log&Report”<br />

on page 469.<br />

Configure the IPS using either the web-based manager or the CLI, then enable or<br />

disable all signatures or all anomalies in individual firewall protection profiles.<br />

Note: If virtual domains are enabled on the <strong>FortiGate</strong> unit, the IPS is configured globally. To<br />

access the IPS, select Global Configuration on the main menu.<br />

Table 35 describes the IPS settings and where to configure and access them.<br />

Table 35: Protection Profile IPS and IPS configuration<br />

Protection Profile IPS options<br />

IPS Signature<br />

Enable or disable IPS signatures by<br />

severity level.<br />

IPS Anomaly<br />

Enable or disable IPS anomalies by<br />

severity level.<br />

Log Intrusions<br />

Enable logging of all signature and<br />

anomaly intrusions.<br />

IPS setting<br />

Intrusion Protection > Signature<br />

View and configure a list of predefined<br />

signatures.<br />

Create custom signatures based on the<br />

network requirements.<br />

Configure protocol decoders.<br />

Intrusion Protection > Anomaly<br />

View and configure a list of predefined<br />

anomalies.<br />

Intrusion Protection > Anomaly > [individual<br />

anomaly]<br />

Enable logging for each signature.<br />

Enable packet logging for each signature or<br />

anomaly.<br />

When to use IPS<br />

To access protection profile IPS options, go to Firewall > Protection Profile,<br />

select Edit or Create New, and select IPS.<br />

IPS is best for large networks or for networks protecting highly sensitive<br />

information. Using IPS effectively requires monitoring and analysis of the attack<br />

logs to determine the nature and threat level of an attack. An administrator can<br />

adjust the threshold levels to ensure a balance between performance and<br />

intrusion prevention.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

412 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!