Protocol decoders
Intrusion Protection
FortiGate Version 4.0 Administration Guide
460
01-400-89802-20090424
To create a custom signature, go to
UTM > Intrusion Protection > Custom
.
Figure 293: Edit Custom Signature
Protocol decoders
The FortiGate Intrusion Protection system uses protocol decoders to identify the abnormal
traffic patterns that do not meet the protocol requirements and standards. For example,
the HTTP decoder monitors traffic to identify any HTTP packets that do not meet the
HTTP protocol standards.
Viewing the protocol decoder list
To view the decoders and the port numbers that the protocol decoders monitor, go to
UTM > Intrusion Protection > Protocol Decoder
. The decoder list is provided for your
reference and can be configured using the CLI. For more information, see the
FortiGate
CLI Reference
.
Figure 294: The protocol decoder list
Note:
Custom signatures must be added to a signature override in an IPS filter to have any
effect. Creating a custom signature is a necessary step, but a custom signature does not
affect traffic simply by being created.
Name
Enter a name for the custom signature.
Signature
Enter the custom signature, using the appropriate syntax. For more information,
see “Custom signature syntax” in the
FortiGate Intrusion Protection System
.
Содержание Gate 60D
Страница 678: ...Reports Log Report FortiGate Version 4 0 Administration Guide 678 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 704: ...Index FortiGate Version 4 0 Administration Guide 704 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 705: ...www fortinet com...
Страница 706: ...www fortinet com...