220
Fortinet Inc.
Detecting attacks
Network Intrusion Detection System (NIDS)
Selecting the interfaces to monitor
1
Go to
NIDS > Detection > General
.
2
Select the interfaces to monitor for network attacks.
You can select one or more interfaces.
3
Select Apply.
Disabling the NIDS
1
Go to
NIDS > Detection > General
.
2
Deselect all monitored interfaces.
3
Select Apply.
Configuring checksum verification
Checksum verification tests files passing through the FortiGate unit to make sure that
they have not been changed in transit. The NIDS can run checksum verification on IP,
TCP, UDP, and ICMP traffic. For maximum detection, you can turn on checksum
verification for all types of traffic. However, if the FortiGate unit does not need to run
checksum verification, you can turn it off for some or all types of traffic to improve
system performance. For example, you might not need to run checksum verification if
your FortiGate unit is installed behind a router that also does checksum verification.
1
Go to
NIDS > Detection > General
.
2
Check the type of traffic on which to run Checksum Verifications.
3
Select Apply.
Figure 33: Example NIDS detection configuration
Summary of Contents for FortiGate 60R
Page 12: ...Contents 12 Fortinet Inc...
Page 26: ...26 Fortinet Inc Customer service and technical support Introduction...
Page 42: ...42 Fortinet Inc Next steps Getting started...
Page 138: ...138 Fortinet Inc Customizing replacement messages System configuration...
Page 228: ...228 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS...
Page 242: ...242 Fortinet Inc Exempt URL list Web filtering...
Page 256: ...256 Fortinet Inc Configuring alert email Logging and reporting...
Page 260: ...260 Fortinet Inc Glossary...
Page 270: ...270 Fortinet Inc Index...