Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
malaz
New Contributor

IPS Default profile

hi,

 

i have enabled the IPS default profile in all the policies, have in my am using FortiGate 1000C version (v5.4.6).

 

does this profile effect the performance of the FortiGate.

 

 

regards.

 

 

2 REPLIES 2
ede_pfau
SuperUser
SuperUser

Yes of course.

On my FGT, there are 5533 IPS signatures in the package. The default IPS sensor leaves out those with 'Low' threat level but there are still thousands left.

It doesn't make sense to apply IPS to traffic which is not covered. For instance, if the policy only allows FTP then only IPS signatures for FTP vulnerabilities should be scanned. Same for client/server addresses, only one subset of signatures applies to each.

You should really create your own set of signatures and granular policies to only apply as much scanning as necessary. The IPS engine can have a substantial effect on the performance of the whole FGT.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
dieter

Keep an eye on your memory usage, you don't want conservative mode...

 

IPS signatures are specific for protecting clients or servers (or both), apply only what is necessary.

 

Eg. IPS security profile "protect_clients" that is applied to rules where clients initiate traffic. Another IPS profile "protect_server" that is applied to rules letting traffic "in" to servers.

 

Mind tho: a server connecting to another server (eg web service) should be considered a client for that traffic !

Labels
Top Kudoed Authors