Fortinet black logo

User Guide

Configuring an intrusion prevention profile

Configuring an intrusion prevention profile

To configure an intrusion prevention profile:
  1. Go to Security > Firewall Objects.
  2. Select Intrusion Prevention Profile from the Security Profiles dropdown.
  3. Select Create or select an existing profile from the list and click Edit.
  4. In the form, enter the following information:

    Settings

    Guidelines

    Name

    Required. Enter a name for the IPS Sensor.

    Comments

    Enter comments about the IPS Sensor.

    Block malicious URLs

    Select to block malicious URLs.

    Scan Outgoing Connections to Botnet Sites

    Choose from the following options:

    • Block: Scan and block outgoing connections to Botnet sites.

    • Disable: Disable scanning outgoing connections to Botnet sites (default).

    • Monitor: Monitor outgoing connections to Botnet sites.

  5. Click Create to add an IPS signature filter to the IPS sensor.

    To edit an IPS signature filter, select an IPS signature filter from the list and then select Edit.

    When editing an IPS signature filter, the fields are the same as when creating it.

    Use the search box to look for an IPS signature filter.

  6. In the Create IPS Signature Filter form, enter the following information:

    Settings

    Guidelines

    Type

    Select either Filter (default) or Signature type.

    Note: When the Type is Signature, you can select a signatures from the list and click Save.

    Use the Search bar to look for a signature.

    Action

    From the dropdown, select one of the following actions:

    • Default (default)

    • Allow

    • Monitor

    • Block

    • Reset

    • Quarantine: Enter the duration of the quarantine, and click Save.

    Packet Logging

    Enable or disable packet logging.

    Status

    Enable, disable, or set the status as default.

    Filter

    Select Edit IPS Filter to edit an IPS filter, enter the following information as shown in Edit IPS Filter.

    Alternatively, from the list, select a preconfigured IPS filter and click Save.

    Use the Search bar to look for an IPS filter.

    Edit IPS Filter

    Severity

    From the dropdown, select severity levels:

    • critical

    • High

    • Medium

    • Low

    • Info

    Target

    From the dropdown, select client and/or server.

    Protocol

    From the dropdown, select protocols.

    OS

    From the dropdown, select OS:

    • bsd

    • Linux

    • MacOS

    • Other

    • Solaris

    • Windows

    Application

    From the dropdown, select applications.

  7. Click Save to save changes to the IPS filter.
  8. Click Save to save changes to the IPS signature filter.
  9. Click Save to save changes to the IPS sensor.

Configuring an intrusion prevention profile

To configure an intrusion prevention profile:
  1. Go to Security > Firewall Objects.
  2. Select Intrusion Prevention Profile from the Security Profiles dropdown.
  3. Select Create or select an existing profile from the list and click Edit.
  4. In the form, enter the following information:

    Settings

    Guidelines

    Name

    Required. Enter a name for the IPS Sensor.

    Comments

    Enter comments about the IPS Sensor.

    Block malicious URLs

    Select to block malicious URLs.

    Scan Outgoing Connections to Botnet Sites

    Choose from the following options:

    • Block: Scan and block outgoing connections to Botnet sites.

    • Disable: Disable scanning outgoing connections to Botnet sites (default).

    • Monitor: Monitor outgoing connections to Botnet sites.

  5. Click Create to add an IPS signature filter to the IPS sensor.

    To edit an IPS signature filter, select an IPS signature filter from the list and then select Edit.

    When editing an IPS signature filter, the fields are the same as when creating it.

    Use the search box to look for an IPS signature filter.

  6. In the Create IPS Signature Filter form, enter the following information:

    Settings

    Guidelines

    Type

    Select either Filter (default) or Signature type.

    Note: When the Type is Signature, you can select a signatures from the list and click Save.

    Use the Search bar to look for a signature.

    Action

    From the dropdown, select one of the following actions:

    • Default (default)

    • Allow

    • Monitor

    • Block

    • Reset

    • Quarantine: Enter the duration of the quarantine, and click Save.

    Packet Logging

    Enable or disable packet logging.

    Status

    Enable, disable, or set the status as default.

    Filter

    Select Edit IPS Filter to edit an IPS filter, enter the following information as shown in Edit IPS Filter.

    Alternatively, from the list, select a preconfigured IPS filter and click Save.

    Use the Search bar to look for an IPS filter.

    Edit IPS Filter

    Severity

    From the dropdown, select severity levels:

    • critical

    • High

    • Medium

    • Low

    • Info

    Target

    From the dropdown, select client and/or server.

    Protocol

    From the dropdown, select protocols.

    OS

    From the dropdown, select OS:

    • bsd

    • Linux

    • MacOS

    • Other

    • Solaris

    • Windows

    Application

    From the dropdown, select applications.

  7. Click Save to save changes to the IPS filter.
  8. Click Save to save changes to the IPS signature filter.
  9. Click Save to save changes to the IPS sensor.