Network Intrusion Detection System (NIDS) | Enabling NIDS attack prevention |
|
|
Figure 35: Example user-defined signature list
Downloading the user-defined signature list
You can back up the
1Go to NIDS > Detection > User Defined Signature List.
2Select Download.
The FortiGate unit downloads the
Preventing attacks
NIDS attack prevention protects the FortiGate unit and the networks connected to it from common TCP, ICMP, UDP, and IP attacks. You can enable the NIDS attack prevention to prevent a set of default attacks with default threshold values. You can also enable and set the threshold values for individual attack signatures.
Note: After the FortiGate unit reboots, the NIDS attack prevention and synflood prevention are always disabled.
•Enabling NIDS attack prevention
•Enabling NIDS attack prevention signatures
•Setting signature threshold values
•Configuring synflood signature values
Enabling NIDS attack prevention
1Go to NIDS > Prevention.
2Select Enable in the top left corner.
225 |