12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring IM/P2P protocols<br />

IM, P2P & VoIP<br />

2 Enter a name for the signature.<br />

3 Enter the signature.<br />

4 Select the severity and what action to perform.<br />

5 Select OK.<br />

To set up the policy for unknown IM users<br />

1 Go to IM, P2P & VoIP > User > Config.<br />

2 Select Allow or Block for each of the four IM applications.<br />

3 Select Apply.<br />

How to configure IM/P2P/VoIP options within a protection profile<br />

There are several areas within a protection profile where you can configure the<br />

IM/P2P/VoIP settings. For more detailed information, see the Firewall Profile<br />

chapter of this guide and the IP, P2P and VoIP Technical Note.<br />

How to configure older versions of IM/P2P applications<br />

Some older versions of IM protocols are able to bypass file blocking because the<br />

message types are not recognized.<br />

Supported IM protocols include:<br />

• MSN 6.0 and above<br />

• ICQ 4.0 and above<br />

• AIM 5.0 and above<br />

• Yahoo 6.0 and above<br />

If you want to block a protocol that is older than the ones listed above, use the CLI<br />

<strong>com</strong>mand: For details see the <strong>FortiGate</strong> CLI Reference.<br />

config imp2p old-version.<br />

How to configure protocols that are not supported<br />

If you find a protocol that is not supported, please ensure that the IPS package is<br />

up to date. If the IPS package is up to date and the protocol is still not supported<br />

you can use the custom signature.<br />

To create a custom signature<br />

1 Go to Intrusion Protection > Signature > Custom > Create New.<br />

2 Enter a name for the signature.<br />

3 Enter the signature.<br />

4 Use the drop down boxes to select an action and the severity for the signature.<br />

5 Select apply.<br />

Note: To detect new IM/P2P applications or new versions of the existing<br />

applications, you only need update the IPS package, available through the<br />

FortiNet Distribution Network (FDN). No firmware upgrade is needed.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

462 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!