Firewall Policy
DoS policies
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
337
•
DoS policies
DoS policies are primarily used to apply DoS sensors to network traffic based on the
FortiGate interface it is leaving or entering as well as the source and destination
addresses. DoS sensors are a traffic anomaly detection feature to identify network traffic
that does not fit known or common traffic patterns and behavior. A common example of
anomalous traffic is the denial of service attack. A denial of service occurs when an
attacking system starts an abnormally large number of sessions with a target system. The
large number of sessions slows down or disables the target system so legitimate users
can no longer use it.
DoS policies examine network traffic very early in the sequence of protective measures
the FortiGate unit deploys to protect your network. Because of this, DoS policies are a
very efficient defence, using few resources. The previously mention denial of service
would be detected and its packets dropped before requiring firewall policy look-ups,
antivirus scans, and other protective but resource-intensive operations.
Viewing the DoS policy list
The DoS policy list displays the DoS policies in their order of matching precedence for
each interface, source/destination address pair, and service.
If virtual domains are enabled on the FortiGate unit, DoS policies are configured
separately for each virtual domain; you must access the VDOM before you can configure
its policies. To access a VDOM, go to
System > VDOM
, and in the row corresponding to
the VDOM whose policies you want to configure, select
Enter
.
You can add, delete, edit, and re-order policies in the DoS policy list. DoS policy order
affects policy matching. As with firewall policies, DoS policies are checked against traffic in
the order in which they appear in the DoS policy list, one at a time, from top to bottom.
When a matching policy is discovered, it is used and further checking for DoS policy
matches are stopped.
To view the DoS policy list, go to
Firewall > Policy > DoS Policy
.
Figure 200: The DoS policy list
Note:
If the firewall policy involves a load balancing virtual IP, the endpoint compliance
check is not performed.
Create New
Add a firewall policy. Select the down arrow beside Create New to add
a firewall policy or firewall policy section. A firewall policy section
visually groups firewall policies. For more information, see
“Configuring DoS policies” on page 338
Column Settings
Customize the table view. You can select the columns to hide or
display and specify the column displaying order in the table.
Section View
Select to display firewall polices organized by interface.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...