![Fortinet FortiGate 1000A Скачать руководство пользователя страница 296](http://html.mh-extra.com/html/fortinet/fortigate-1000a/fortigate-1000a_administration-manual_2321799296.webp)
296
01-28011-0254-20051115
Fortinet Inc.
Signature
IPS
Table 32
describes each possible action you can select for predefined signatures.
Configuring predefined signatures
To enable or disable predefined signature groups
1
Go to
IPS > Signature > Predefined
.
Revision
The revision number for individual signatures. To show the signature group
members, click on the blue triangle.
Modify
The Configure and Reset icons. Reset only appears when the default
settings have been modified. Selecting Reset restores the default settings.
Table 32: Actions to select for each predefined signature
Action
Description
Pass
When a packet triggers a signature, the FortiGate unit generates an alert
and allows the packet through the firewall without further action.
If logging is disabled and action is set to Pass, the signature is effectively
disabled.
Drop
When a packet triggers a signature, the FortiGate unit generates an alert
and drops the packet. The session is not touched.
Fortinet recommends using an action other than Drop for TCP connection
based attacks.
Reset
When a packet triggers a signature, the FortiGate unit generates an alert
and drops the packet. The FortiGate unit sends a reset to both the client
and the server and drops the session from the session table.
This is used for TCP connections only. If set for non-TCP connection
based attacks, the action will behave as Clear Session. If the Reset action
is triggered before the TCP connection is fully established, it acts as Clear
Session.
Reset Client
When a packet triggers a signature, the FortiGate unit generates an alert
and drops the packet. The FortiGate unit sends a reset to the client and
drops the session from the session table.
This is used for TCP connections only. If set for non-TCP connection
based attacks, the action will behave as Clear Session. If the Reset Client
action is triggered before the TCP connection is fully established, it acts as
Clear Session.
Reset Server
When a packet triggers a signature, the FortiGate unit generates an alert
and drops the packet. The FortiGate unit sends a reset to the server and
drops the session from the session table.
This is used for TCP connections only. If set for non-TCP connection
based attacks, the action will behave as Clear Session. If the Reset Server
action is triggered before the TCP connection is fully established, it acts as
Clear Session.
Drop Session
When a packet triggers a signature, the FortiGate unit generates an alert
and drops the packet. For the remainder of this packet’s session, all
follow-up packets are dropped.
Clear Session
When a packet triggers a signature, the FortiGate unit generates an alert
and the session to which the packet belongs is removed from the session
table immediately. No reset is sent.
For TCP, all follow-up packets could be dropped.
For UDP, all follow-up packets could trigger the firewall to create a new
session.
Pass Session
When a packet triggers a signature, the FortiGate unit generates an alert
and allows the packet through the firewall. For the remainder of this
packet’s session, the IPS is bypassed by all follow-up packets.
Содержание FortiGate 1000A
Страница 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Страница 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Страница 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Страница 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Страница 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Страница 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Страница 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...