Network Intrusion Detection System (NIDS)
Detecting attacks
FortiGate-50A Installation and Configuration Guide
217
Viewing the signature list
You can display the current list of NIDS signature groups and the members of a
signature group.
To view the signature list
1
Go to
NIDS > Detection > Signature List
.
2
View the names and action status of the signature groups in the list.
The NIDS detects attacks listed in all the signature groups that have check marks in
the Enable column.
3
Select View Details
.to display the members of a signature group.
The Signature Group Members list displays the attack ID, Rule Name, and Revision
number for each group member.
Viewing attack descriptions
Fortinet provides online information for all NIDS attacks. You can view the
FortiResponse Attack Analysis web page for an attack listed on the signature list.
To view attack descriptions
1
Go to
NIDS > Detection > Signature List
.
2
Select View Details
.to display the members of a signature group.
3
Select a signature and copy its attack ID.
4
Open a web browser and enter the following URL:
http://www.fortinet.com/ids/ID<attack-ID>
Make sure that you include the attack ID.
For example, to view the Fortinet Attack Analysis web page for the
ssh CRC32
overflow /bin/sh
attack (ID 101646338), use the following URL:
http://www.fortinet.com/ids/ID101646338
Note:
The user-defined signature group is the last item in the signature list. See
“Adding user-
defined signatures” on page 218
.
Note:
Each attack log message includes a URL that links directly to the FortiResponse Attack
Analysis web page for that attack. This URL is available in the Attack Log messages and Alert
email messages. For information about log message content and formats, and about log
locations, see the
FortiGate
Logging and Message Reference Guide.
For information about
logging attack messages, see
“Logging attacks” on page 222
.
Содержание FortiGate 50A
Страница 12: ...Contents 12 Fortinet Inc ...
Страница 32: ...32 Fortinet Inc Next steps Getting started ...
Страница 40: ...40 Fortinet Inc Completing the configuration NAT Route mode installation ...
Страница 72: ...72 Fortinet Inc Session list System status ...
Страница 112: ...112 Fortinet Inc Configuring the modem interface Network configuration ...
Страница 120: ...120 Fortinet Inc Adding RIP filters RIP configuration ...
Страница 170: ...170 Fortinet Inc Content profiles Firewall configuration ...
Страница 224: ...224 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS ...
Страница 230: ...230 Fortinet Inc Viewing the virus list Antivirus protection ...
Страница 244: ...244 Fortinet Inc Exempt URL list Web filtering ...
Страница 262: ...262 Fortinet Inc Glossary ...
Страница 272: ...272 Fortinet Inc Index ...