12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Intrusion Protection<br />

Anomalies<br />

Viewing the traffic anomaly list<br />

To view the anomaly list, go to Intrusion Protection > Anomaly.<br />

Figure 285:A portion of the traffic anomaly list<br />

View traffic<br />

anomalies with<br />

severity<br />

Name<br />

Enable<br />

Logging<br />

Action<br />

Severity<br />

Edit icon<br />

Reset icon<br />

Configuring IPS traffic anomalies<br />

Select filters then select Go to view only those anomalies that match the<br />

filter criteria. Sort criteria can be = to All, Information, Low,<br />

Medium, High, or Critical.<br />

The traffic anomaly name.<br />

The status of the traffic anomaly. A check mark in the box indicates the<br />

anomaly signature is enabled.<br />

The logging status for each traffic anomaly. A check mark in the box<br />

indicates logging is enabled for the anomaly.<br />

The action set for each traffic anomaly. Action can be Pass, Drop, Reset,<br />

Reset Client, Reset Server, Drop Session, Clear Session, or Pass<br />

Session. If logging is enabled, the action appears in the status field of the<br />

log message generated by the Anomaly. See Table 36 for descriptions of<br />

the actions.<br />

The severity level set for each traffic anomaly. Severity level can be<br />

Information, Low, Medium, High, or Critical. Severity level is set for<br />

individual anomalies.<br />

Select to edit the following information: Action, Severity, and Threshold.<br />

The Reset icon is displayed only if an anomaly has been modified. Use<br />

the Reset icon to restore modified settings to the re<strong>com</strong>mended values.<br />

Each IPS traffic anomaly is preset with a re<strong>com</strong>mended configuration. Use the<br />

re<strong>com</strong>mended configurations, or modify the re<strong>com</strong>mended configurations to meet the<br />

needs of your network.<br />

To configure IPS traffic anomalies, go to Intrusion Protection > Anomaly.<br />

Figure 286:Edit IPS Traffic Anomaly: icmp_dst_session<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 421

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!