Protocol decoders

Protocol decoders

Protocol decoders

This section describes:

Protocol decoders

Upgrading the IPS protocol decoder list

Viewing the protocol decoder list

Protocol decoders

The FortiGate IPS uses protocol decoders to identify the abnormal traffic patterns that do not meet the protocol requirements and standards. For example, the HTTP decoder monitors the HTTP traffic to identify any HTTP packets that do not meet the HTTP protocol standards.

On the Intrusion Protection > Signature > Protocol Decoder page, you can view the decoders and the port numbers the protocol decoders monitor.

Upgrading the IPS protocol decoder list

The Intrusion Protection system protocol decoders are upgraded automatically through the FortiGuard Distribution Network (FDN) if existing decoders are modified or new decoders added. The FDN keeps the protocol decoder list up-to- date with protection against new threats such as the latest versions of existing IM/P2P as well as against new applications.

FortiGate IPS User Guide Version 3.0 MR7

 

01-30007-0080-20080916

37

Page 37
Image 37
Fortinet manual Protocol decoders, Upgrading the IPS protocol decoder list