Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kiandra
New Contributor

IPS signature severity

I configured the IPS and DoS on our Fortigate E seriesto protect against TCP & UDP scans, floods and ICMP sweeps. These include blocking source IPS and quarantine them. I got it to the point which is giving satisfying results. The purpose was to protect the network from enumeration attacks.

The problem is on the reporting. The IPS reports always shows all Critical leaving on the top list the scans. 

Nowadays scans are everywhere, bots are automatically scanning subnets and running attacks. I don't care about them as they are getting blocked and quarantined, but they look bad on a report and do not allow to highlight the real Critical threats. 

I wanted to find a way to change the severity of such signatures or DoS anomaly sensors, but all DoS profiles are all marked as Critical. I contacted support and they confirmed that IPS signatures and DoS profiles severity cannot be changed. Creating a custom signature is useless for this as we don't know every signature and they can't be cloned or edited.

Could the Fortinet developers add such feature? To allow to change the severity of a signature, category or DoS profile?

0 REPLIES 0
Labels
Top Kudoed Authors