Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dieter
New Contributor

log all IPS hits

Hi, new on the forums and fairly new to Fortigate.

 

So...

The default action on a lot of IPS signatures is Pass. But action Pass produces no logging!

I would like to at least log ALL hits to any signature.

 

Can this be done easily?

[ul]
  • An IPS Filter (which allows changing the action for a set of signatures) does not allow for filtering on the default action.
  • Adding all signatures manually is not feasible (nor manageable), a few thousand signatures would have to be added manually...[/ul]
  • 2 REPLIES 2
    oheigl
    Contributor II

    You can add two IPS filters, one for target client, one for target server, that's all signatures. Then set the action to monitor.

    Or do it with every severity and for the high and critical set the action to block. This is just a task which takes a few minutes

    dieter
    New Contributor

    As a sidenote: I keep IPS sensors separate for servers (IPS Sensor protect_servers) and clients (IPS Sensor protect_clients), based on target filter. Currently protect_servers blocks every.

     

    Good suggestion about using severity. For protect_clients I could make a filter (target client + severity X) for each severity (5 levels).

     

    You actually have to read my question in the context of me coming from a different firewall vendor: I would like to use the Default action for anything that does not have Pass for default action.

    Although I realise that currently makes no sense: the only other default action Fortinet uses in the IPS database is Block (no actions Reset and Monitor).

    Labels
    Top Kudoed Authors