Network Intrusion Detection System (NIDS)
Preventing attacks
FortiGate-60R Installation and Configuration Guide
223
Figure 35: Example user-defined signature list
Downloading the user-defined signature list
You can back up the user-defined signature list by downloading it to a text file on the
management computer.
1
Go to
NIDS > Detection > User Defined Signature List
.
2
Select Download.
The FortiGate unit downloads the user-defined signature list to a text file on the
management computer. You can specify a location to which to download the text file
as well as a name for the text file.
Preventing attacks
NIDS attack prevention protects the FortiGate unit and the networks connected to it
from common TCP, ICMP, UDP, and IP attacks. You can enable the NIDS attack
prevention to prevent a set of default attacks with default threshold values. You can
also enable and set the threshold values for individual attack signatures.
•
Enabling NIDS attack prevention
•
Enabling NIDS attack prevention signatures
•
Setting signature threshold values
•
Configuring synflood signature values
Enabling NIDS attack prevention
1
Go to
NIDS > Prevention
.
2
Select Enable in the top left corner.
Note:
After the FortiGate unit reboots, the NIDS attack prevention and synflood prevention are
always disabled.
Содержание FortiGate 60R
Страница 12: ...Contents 12 Fortinet Inc...
Страница 26: ...26 Fortinet Inc Customer service and technical support Introduction...
Страница 42: ...42 Fortinet Inc Next steps Getting started...
Страница 106: ...106 Fortinet Inc Registering a FortiGate unit after an RMA Virus and attack definitions updates and registration...
Страница 138: ...138 Fortinet Inc Customizing replacement messages System configuration...
Страница 228: ...228 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS...
Страница 242: ...242 Fortinet Inc Exempt URL list Web filtering...
Страница 256: ...256 Fortinet Inc Configuring alert email Logging and reporting...
Страница 260: ...260 Fortinet Inc Glossary...
Страница 270: ...270 Fortinet Inc Index...