12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Intrusion Protection<br />

Predefined signatures<br />

Small businesses and home offices without network administrators may be<br />

overrun with attack log messages and not have the networking background<br />

required to configure the thresholds and other IPS settings.<br />

In addition, the other protection features in the <strong>FortiGate</strong> unit, such as antivirus<br />

(including grayware), spam filters, and web filters offer excellent protection for all<br />

networks.<br />

Predefined signatures<br />

By default, not all signatures are enabled. But logging of all signatures is enabled.<br />

Check the default settings to ensure they meet the requirements of the network<br />

traffic.<br />

Disabling unneeded signatures can improve system performance and reduce the<br />

number of log messages and alert email messages the IPS generates. For<br />

example, the IPS detects a large number of web server attacks. If access to a web<br />

server behind the <strong>FortiGate</strong> unit is not provided, disable all web server attack<br />

signatures.<br />

Note: By allowing your IPS signature settings to run on default, you may be slowing down<br />

the overall performance of the <strong>FortiGate</strong> unit. By fine tuning the predefined signature and<br />

logging setting, you can ensure maximum performance as well as maximum protection.<br />

See “Fine tuning IPS predefined signatures for enhanced system performance” on<br />

page 416<br />

Viewing the predefined signature list<br />

Enable or disable and configure the settings for individual predefined signatures<br />

from the predefined signature list.<br />

Note: If virtual domains are enabled on the <strong>FortiGate</strong> unit, the IPS is configured globally. To<br />

access the IPS, select Global Configuration on the main menu.<br />

To view the predefined signature list, go to Intrusion Protection > Signature ><br />

Predefined. You can also use filters to display the signatures you want to view.<br />

For details, see “Using display filters” on page 415.<br />

Figure 280:Predefined signature list<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 413

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!