Skip to main content
Quint021
Staff
Staff
March 25, 2025

Technical Tip: How to allow IP/Device through Intrusion Prevention while logging associated Signatures

  • March 25, 2025
  • 0 replies
  • 428 views
Description This article describes how to allow a device such as a Vulnerability Scanner for Intrusion Prevention while simultaneously logging the signatures generated from the machine.
Scope FortiGate.
Solution

In some scenarios, Administrators want to allow specific devices/scanners while enabling Intrusion Prevention logging for monitoring and analysis purposes. To achieve this, the following setup is required: Custom IPS Profile Creation with the action set to monitor for all signatures - FortiGate administration guide.

Monitor_ALL.PNG

 

Firewall Policies Required:


Policy Setup.PNG