12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Predefined signatures<br />

Intrusion Protection<br />

Column<br />

Settings<br />

Select to customize the signature information to display in the table. You<br />

can also readjust the column order.<br />

By default, the signature ID, group name, and revision number are not<br />

displayed.<br />

Clear All Filters If you have applied column filtering, select this option to clear all filters<br />

and display all the signatures.<br />

Name<br />

Name of the signature.<br />

Enable<br />

Logging<br />

Action<br />

Severity<br />

Protocols<br />

OS<br />

Applications<br />

ID<br />

Group<br />

Revision<br />

Configure icon<br />

Reset icon<br />

The status of the signature. A green circle indicates the signature is<br />

enabled. A gray circle indicates the signature is not enabled.<br />

The logging status of the signature. By default, logging is enabled for all<br />

signatures. If logging is enabled, the action appears in the status field of<br />

the log message generated by the signature.<br />

The action set for the signature. Action can be Pass, Drop, Reset, Reset<br />

Client, Reset Server, Drop Session, Clear Session, or Pass Session. If<br />

logging is enabled, the action appears in the status field of the log<br />

message generated by the signature. See Table 36 for descriptions of<br />

the actions.<br />

The severity level set for the signature. Severity level can be set to<br />

Information, Low, Medium, High, or Critical.<br />

The protocol the signature applies to.<br />

The operating system the signature applies to.<br />

The applications the signature applies to.<br />

The signature’s unique ID.<br />

The name of the signature group that the signature belongs to.<br />

The revision number of the signature.<br />

Configure settings for the signature.<br />

Reset only appears when the default settings for a signature have been<br />

modified. Selecting Reset for a signature restores the default settings.<br />

Table 36 describes each possible action to take for predefined signatures, custom<br />

signatures and anomalies.<br />

Table 36: Actions to select for each predefined signature<br />

Action<br />

Pass<br />

Drop<br />

Reset<br />

Description<br />

When a packet triggers a signature, the <strong>FortiGate</strong> unit generates an<br />

alert and allows the packet through the firewall without further action.<br />

If logging is disabled and action is set to Pass, the signature is<br />

effectively disabled.<br />

When a packet triggers a signature, the <strong>FortiGate</strong> unit generates an<br />

alert and drops the packet. The firewall session is not touched.<br />

Fortinet re<strong>com</strong>mends using an action other than Drop for TCP<br />

connection based attacks.<br />

When a packet triggers a signature, the <strong>FortiGate</strong> unit generates an<br />

alert and drops the packet. The <strong>FortiGate</strong> unit sends a reset to both<br />

the client and the server and drops the firewall session from the<br />

firewall session table.<br />

This is used for TCP connections only. If set for non-TCP connection<br />

based attacks, the action will behave as Clear Session. If the Reset<br />

action is triggered before the TCP connection is fully established, it<br />

acts as Clear Session.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

414 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!