12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Custom signatures<br />

Intrusion Protection<br />

Name<br />

Enable<br />

Logging<br />

Action<br />

Severity<br />

Delete icon<br />

Edit icon<br />

The custom signature name.<br />

The status of each custom signature. A check mark in the box indicates<br />

the signature is enabled.<br />

The logging status of each custom signature. A check mark in the box<br />

indicates logging is enabled for the custom signature.<br />

The action set for each custom signature. Action can be Pass, Drop,<br />

Reset, Reset Client, Reset Server, Drop Session, Clear Session, or<br />

Pass Session. If logging is enabled, the action appears in the status field<br />

of the log message generated by the signature. See Table 36 for<br />

descriptions of the actions.<br />

The severity level set for each custom signature. Severity level can be<br />

Information, Low, Medium, High, or Critical. Severity level is set for<br />

individual signatures.<br />

Select to delete the custom signature.<br />

Select to edit the following information: Name, Signature, Action, Packet<br />

Log, and Severity.<br />

Creating custom signatures<br />

Use custom signatures to block or allow specific traffic. For example, to block<br />

traffic containing pornography, add custom signatures similar to the following:<br />

F-SBID (--protocol tcp; --flow established; --content "nude cheerleader"; --<br />

no_case)<br />

When adding the signature, set action to Drop Session.<br />

For more information on custom signature syntax, see the <strong>FortiGate</strong> Intrusion<br />

Protection System (IPS) <strong>Guide</strong>.<br />

Note: Custom signatures are an advanced feature. This document assumes the user has<br />

previous experience creating intrusion detection signatures.<br />

To create a custom signature, go to Intrusion Protection > Signature > Custom.<br />

Figure 283:Edit Custom Signature<br />

Name<br />

Signature<br />

Action<br />

Packet Log<br />

Severity<br />

Enter a name for the custom signature.<br />

Enter the custom signature. For more information about custom<br />

signature syntax, see “Custom signature syntax” in the <strong>FortiGate</strong><br />

Intrusion Protection System (IPS) <strong>Guide</strong>.<br />

Select an action from the list. Action can be Pass, Drop, Reset, Reset<br />

Client, Reset Server, Drop Session, Pass Session, or Clear Session.<br />

See Table 36 for descriptions of the actions.<br />

Enable packet logging.<br />

Select a severity level from the dropdown list. Severity level can be<br />

Information, Low, Medium, High, or Critical. Severity level is set for<br />

individual signatures.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

418 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!