
196
Fortinet Inc.
Detecting attacks
Network Intrusion Detection System (NIDS)
Enabling and disabling NIDS attack signatures
By default, all NIDS attack signatures are enabled. You can use the NIDS signature
list to disable detection of some attacks. Disabling unnecessary NIDS attack
signatures can improve system performance and reduce the number of IDS log
messages and alert emails that the NIDS generates. For example, the NIDS detects a
large number of web server attacks. If you do not provide access to a web server
behind your firewall, you might want to disable all web server attack signatures.
To disable NIDS attack signatures:
1
Go to
NIDS > Detection > Signature List
.
2
Scroll down the signature list to find the signature group to disable.
Attack ID numbers and rule names in attack log messages and alert email match
those in the signature group members list. You can scroll through a signature group
members list to locate specific attack signatures by ID number and name.
3
Uncheck the Enable check box.
4
Select OK.
5
Repeat steps
2
to
4
for each NIDS attack signature group that you want to disable.
Select Check All
to enable all NIDS attack signature groups in the signature list.
Select Uncheck All
to disable all NIDS attack signature groups in the signature
list.
Adding user-defined signatures
You can create a user-defined signature list in a text file and upload it from the
management computer to the FortiGate unit.
For information about how to write user-defined signatures, see the
FortiGate NIDS
Guide
.
1
Go to
NIDS > Detection > User Defined Signature List
.
2
Select Upload.
3
Type the path and filename of the text file for the user-defined signature list or select
Browse and locate the file.
4
Select OK to upload the text file for the user-defined signature list.
5
Select Return to display the uploaded user-defined signature list.
Note:
To save your NIDS attack signature settings, Fortinet recommends that you back up your
FortiGate configuration before you update the firmware and restore the saved configuration
after the update.
Содержание FortiGate 50R
Страница 16: ...16 Fortinet Inc Customer service and technical support Introduction ...
Страница 32: ...32 Fortinet Inc Next steps Getting started ...
Страница 40: ...40 Fortinet Inc Completing the configuration NAT Route mode installation ...
Страница 112: ...112 Fortinet Inc Customizing replacement messages System configuration ...
Страница 144: ...144 Fortinet Inc Content profiles Firewall configuration ...
Страница 202: ...202 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS ...
Страница 216: ...216 Fortinet Inc Exempt URL list Web filtering ...
Страница 228: ...228 Fortinet Inc Configuring alert email Logging and reporting ...
Страница 232: ...232 Fortinet Inc Glossary ...