Detecting attacks

Network Intrusion Detection System (NIDS)

 

 

Selecting the interfaces to monitor

1Go to NIDS > Detection > General.

2Select the interfaces to monitor for network attacks.

You can select up to 4 interfaces and VLAN subinterfaces.

3Select Apply.

Disabling the NIDS

1Go to NIDS > Detection > General.

2Deselect all monitored interfaces.

3Select Apply.

Configuring checksum verification

Checksum verification tests files passing through the FortiGate unit to make sure that they have not been changed in transit. The NIDS can run checksum verification on IP, TCP, UDP, and ICMP traffic. For maximum detection, you can turn on checksum verification for all types of traffic. However, if the FortiGate unit does not need to run checksum verification, you can turn it off for some or all types of traffic to improve system performance. For example, you might not need to run checksum verification if your FortiGate unit is installed behind a router that also does checksum verification.

1Go to NIDS > Detection > General.

2Check the type of traffic on which to run Checksum Verifications.

3Select Apply.

Figure 33: Example NIDS detection configuration

250

Fortinet Inc.

Page 250
Image 250
Fortinet 400 manual Selecting the interfaces to monitor, Disabling the Nids, Configuring checksum verification, 250