300
01-28011-0254-20051115
Fortinet Inc.
Anomaly
IPS
Adding custom signatures
To add a custom signature
1
Go to
IPS > Signature > Custom
.
2
Select Create New to add a new custom signature or select the Edit icon to edit an
existing custom signature.
Figure 155:Edit custom signature
3
Enter a name for the custom signature.
You cannot edit the name of an existing custom signature.
4
Enter the custom signature.
5
Select the action to be taken when a packet triggers this signature. (See
Table 32
for
action descriptions.)
6
Select the Logging box to enable logging for the custom signature or clear the Logging
box to disable logging for the custom signature.
Backing up and restoring custom signature files
For information on backing up and restoring the custom signature list, see
“Backing up
and Restoring” on page 130
.
Anomaly
The FortiGate IPS uses anomaly detection to identify network traffic that does not fit
known or preset traffic patterns. The FortiGate IPS identifies the four statistical
anomaly types for the TCP, UDP, and ICMP protocols.
!
Caution:
Restoring the custom signature list overwrites the existing file.
Flooding
If the number of sessions targeting a single destination in one second is
over a threshold, the destination is experiencing flooding.
Scan
If the number of sessions from a single source in one second is over a
threshold, the source is scanning.
Source session
limit
If the number of concurrent sessions from a single source is over a
threshold, the source session limit is reached.
Destination
session limit
If the number of concurrent sessions to a single destination is over a
threshold, the destination session limit is reached.
Содержание FortiGate 1000A
Страница 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Страница 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Страница 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Страница 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Страница 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Страница 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Страница 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...