Fortinet IPS DoS sensor attributes, Anomaly configuration, Will appear in the DoS sensor list

Page 47

 

 

DoS sensors

Configuring DoS sensors

Figure 13: Edit DoS Sensor

DoS sensor attributes:

Name

Enter or change the DoS sensor name.

Comments

Enter or change an optional description of the DoS sensor. This description

 

will appear in the DoS sensor list.

Anomaly configuration:

Name

The name of the anomaly.

Enable

Select the check box to enable the DoS sensor to detect when the

 

specified anomaly occurs. Selecting the check box in the header row will

 

enable sensing of all anomalies.

Logging

Select the check box to enable the DoS sensor to log when the anomaly

 

occurs. Selecting the check box in the header row will enable logging for all

 

anomalies. Anomalies that are not enabled are not logged.

Action

Select Pass to allow anomalous traffic to pass when the FortiGate unit

 

detects it, or set Block to prevent the traffic from passing.

Threshold

Displays the number of sessions/packets that must show the anomalous

 

behavior before the FortiGate unit triggers the anomaly action (pass or

 

block). If required, change the number. For more information about how

 

these settings affect specific anomalies, see Table 10 on page 48.

FortiGate IPS User Guide Version 3.0 MR7

 

01-30007-0080-20080916

47

Image 47
Contents E R G U I D E Trademarks Contents SYN flood attacks Protocol decodersIPS sensors DoS sensorsFortiGate IPS IntroductionTypographic conventions About this documentFortinet documentation Document conventionsFortiGate Pptp VPN User Guide Comments on Fortinet technical documentation Customer service and technical supportFortinet Knowledge Center This section contains the following topics IPS overview and general configurationIPS settings and controls Config ips global Set fail-open enable disable end When to use IPSDefault signature and anomaly settings Default fail open settingControlling sessions Setting the buffer sizeConfiguring logging and alert email Monitoring the network and dealing with attacksAttack log messages Signature FortiGuard Center AnomalySelect Create New Using IPS sensors in a protection profileCreating a protection profile that uses IPS sensors Adding protection profiles to firewall policiesAdding protection profiles to user groups Using IPS sensors in a protection profile Viewing the predefined signature list Predefined signaturesIPS predefined signatures Clear All Filters SettingsEnable ColumnCreate a sensor and add IPS filters to it Viewing the predefined signature list Viewing the custom signature list Custom signaturesIPS custom signatures Command syntax pattern Custom signature configurationAdding custom signatures using the web-based manager Adding custom signatures using the CLIShows the valid characters for custom signature fields Creating custom signaturesCustom signature fields Srcport Custom signature syntaxAttackid Name BufferOverflowContent keywords Keyword and value Description Deprecated, see pattern and context keywords Context host Pattern GETContext uri Pattern yahoo.comUri !uristr PcreRegex/mdelim RegexdelimismxAEGRUIP header keywords Keyword and Value Description Protocol tcpTCP header keywords Keyword and Value Description Tcpflags S,12 Tcpflags APOther keywords Keyword and Value Description UDP header keywords Keyword and Value DescriptionIcmp keywords Keyword and Value Usage Sbid --name Block.example.com Example 1 signature to block access to example.comExample custom signatures Sbid --name Block.example.com Sbid --name Block.SMTP.VRFY.CMD --pattern vrfy Example 2 signature to block the Smtp ‘vrfy’ commandSbid --name Block.SMTP.VRFY.CMD Creating custom signatures Upgrading the IPS protocol decoder list Protocol decodersProtocol decoders Protocol decoder list Protocols Protocol decoder names Port Viewing the protocol decoder listViewing the IPS sensor list AlldefaultAlldefaultpass IPS sensorsProtectemailserver Configuring IPS sensorsAdding an IPS sensor ProtectclientIPS sensor filters IPS sensor attributesDelete and Edit Delete or edit the filter Icons Configuring filtersReset IPS sensor overridesApplication Configuring pre-defined and custom overridesSource Exempt IPDoS sensors Appears, and select OK Configuring DoS sensorsViewing the DoS sensor list Sequence in which the sensors examine network trafficWill appear in the DoS sensor list Anomaly configurationDoS sensor attributes Name Enter or change the DoS sensor name CommentsUnderstanding the anomalies Udpsrcsession Anomaly Description TcpdstsessionUdpflood UdpscanUnderstanding the anomalies How SYN floods work What is a SYN flood attack?SYN flood attacks How IPS works to prevent SYN floods What is SYN threshold?What is SYN proxy? FortiGate IPS Response to SYN flood attacksIPS operation before synflood threshold is reached Configure the options for tcpsynflood Select OK Configuring SYN flood protectionSuggested settings for different network conditions FortiGate IPS response to Icmp sweep attacks What is an Icmp sweep?Icmp sweep attacks How Icmp sweep attacks workPredefined Icmp signatures Icmp sweep anomalies Configuring Icmp sweep protection FortiGate Version 3.0 MR7 IPS User Guide IndexTechnical support