Network Intrusion Detection System (NIDS) | Preventing attacks |
Setting signature threshold values
You can change the default threshold values for the NIDS Prevention signatures listed in Table 20. The threshold depends on the type of attack. For flooding attacks, the threshold is the maximum number of packets received per second. For overflow attacks, the threshold is the buffer size for the command. For large ICMP attacks, the threshold is the ICMP packet size limit to pass through.
For example, setting the icmpflood signature threshold to 500 allows 500 echo requests from a source address, to which the system sends echo replies. The FortiGate unit drops any requests over the threshold of 500.
If you enter a threshold value of 0 or a number out of the allowable range, the
FortiGate unit uses the default value.
Table 20: NIDS Prevention signatures with threshold values
Signature | Threshold value units | Default | Minimum | Maximum |
abbreviation |
| threshold | threshold | threshold |
| value | value | value |
synflood | Threshold: Maximum number of SYN | 2048 | 1 | 1000000 |
| segments received per second. |
| Queue Size: Maximum proxied | 4096 | 100 | 1000000 |
| connections. |
| Timeout: Number of seconds for the | 15 | 1 | 3600 |
| SYN cookie to keep a proxied |
| connection alive. |
portscan | Maximum number of SYN segments | 512 | 1 | 1000000 |
| received per second |
srcsession | Total number of TCP sessions initiated | 2048 | 1 | 1000000 |
| from the same source |
ftpovfl | Maximum buffer size for an FTP | 256 | 32 | 1408 |
| command (bytes) |
smtpovfl | Maximum buffer size for an SMTP | 512 | 32 | 1408 |
| command (bytes) |
pop3ovfl | Maximum buffer size for a POP3 | 512 | 32 | 1408 |
| command (bytes) |
udpflood | Maximum number of UDP packets | 2048 | 1 | 1000000 |
| received from the same source or sent |
| to the same destination per second |
udpsrcsession | Total number of UDP sessions initiated | 2048 | 1 | 1000000 |
| from the same source |
icmpflood | Maximum number of ICMP packets | 256 | 1 | 1000000 |
| received from the same source or sent |
| to the same destination per second |
icmpsrcsession | Total number of ICMP sessions | 128 | 1 | 1000000 |
| initiated from the same source |
icmpsweep | Maximum number of ICMP packets | 128 | 1 | 1000000 |
| received from the same source per |
| second |
icmplarge | Maximum ICMP packet size (bytes) | 32000 | 64 | 64000 |
221 |