Network Intrusion Detection System (NIDS)

Preventing attacks

 

 

Setting signature threshold values

You can change the default threshold values for the NIDS Prevention signatures listed in Table 40. The threshold depends on the type of attack. For flooding attacks, the threshold is the maximum number of packets received per second. For overflow attacks, the threshold is the buffer size for the command. For large ICMP attacks, the threshold is the ICMP packet size limit to pass through.

For example, setting the icmpflood signature threshold to 500 allows 500 echo requests from a source address, to which the system sends echo replies. The FortiGate unit drops any requests over the threshold of 500.

If you enter a threshold value of 0 or a number out of the allowable range, the

FortiGate unit uses the default value.

Table 40: NIDS Prevention signatures with threshold values

Signature

Threshold value units

Default

Minimum

Maximum

abbreviation

 

threshold

threshold

threshold

 

 

value

value

value

 

 

 

 

 

synflood

Threshold: Maximum number of SYN

2048

1

1000000

 

segments received per second.

 

 

 

 

 

 

 

 

 

Queue Size: Maximum proxied

4096

100

1000000

 

connections.

 

 

 

 

 

 

 

 

 

Timeout: Number of seconds for the

15

1

3600

 

SYN cookie to keep a proxied

 

 

 

 

connection alive.

 

 

 

 

 

 

 

 

portscan

Maximum number of SYN segments

512

1

1000000

 

received per second

 

 

 

 

 

 

 

 

srcsession

Total number of TCP sessions initiated

2048

1

1000000

 

from the same source

 

 

 

 

 

 

 

 

ftpovfl

Maximum buffer size for an FTP

256

32

1408

 

command (bytes)

 

 

 

 

 

 

 

 

smtpovfl

Maximum buffer size for an SMTP

512

32

1408

 

command (bytes)

 

 

 

 

 

 

 

 

pop3ovfl

Maximum buffer size for a POP3

512

32

1408

 

command (bytes)

 

 

 

 

 

 

 

 

udpflood

Maximum number of UDP packets

2048

1

1000000

 

received from the same source or sent

 

 

 

 

to the same destination per second

 

 

 

 

 

 

 

 

udpsrcsession

Total number of UDP sessions initiated

2048

1

1000000

 

from the same source

 

 

 

 

 

 

 

 

icmpflood

Maximum number of ICMP packets

256

1

1000000

 

received from the same source or sent

 

 

 

 

to the same destination per second

 

 

 

 

 

 

 

 

icmpsrcsession

Total number of ICMP sessions

128

1

1000000

 

initiated from the same source

 

 

 

 

 

 

 

 

icmpsweep

Maximum number of ICMP packets

128

1

1000000

 

received from the same source per

 

 

 

 

second

 

 

 

 

 

 

 

 

icmplarge

Maximum ICMP packet size (bytes)

32000

64

64000

 

 

 

 

 

FortiGate-800 Installation and Configuration Guide

275

Page 275
Image 275
Fortinet FortiGate-800 manual Setting signature threshold values, 275