12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Intrusion Protection<br />

Protocol Decoders<br />

Protocol Decoders<br />

The <strong>FortiGate</strong> IPS uses protocol decoders to identify the abnormal traffic patterns<br />

that do not meet the protocol requirements and standards. For example, the<br />

HTTP decoder monitors the HTTP traffic to identify any HTTP packets that do not<br />

meet the HTTP protocol standards.<br />

On the Intrusion Protection > Signature > Protocol Decoder page, you can<br />

view the decoders and configure the port numbers that the protocol decoders<br />

monitor. To configure other decoder settings, such as action and packet logging,<br />

you must go to Intrusion Protection > Signature > Predefined.<br />

Note: If virtual domains are enabled on the <strong>FortiGate</strong> unit, the IPS is configured globally. To<br />

access the IPS, select Global Configuration on the main menu.<br />

Viewing the protocol decoder list<br />

To view the decoder list, go to Intrusion Protection > Signature > Protocol<br />

Decoder.<br />

Figure 284:Portion of the protocol decoder list<br />

Name<br />

Ports<br />

Configure icon<br />

The protocol decoder name.<br />

The port number or numbers the decoder monitors.<br />

Click to modify the signature port settings. You cannot modify settings of<br />

some decoders used by the system.<br />

Configuring IPS protocol decorders<br />

On the Protocol Decorders page, you can modify the port numbers that the<br />

decorders monitor. You cannot modify port settings of some decoders used by the<br />

system.<br />

On the Intrusion Protection > Signature > Predefined page, you can modify the<br />

decorders’ other settings, such as action and packet logging.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 419

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!