Technical Tip: How to block a signature
Description
This article describes how to choose a signature in an IPS profile and change the default action.
Scope
FortiGate.
Solution
- Go to Security Profiles -> Intrusion Prevention, select an IPS profile, and select ‘Edit’.
- Under ‘IPS Signatures and Filters’, select ‘Create New’.
- Under the ‘Add signatures’ page, make sure Type is set to ‘Signature’. Search for a signature to block. In this example, it is ‘MS.Windows.Server.HTTP.sys.DoS’. Select that signature and select ‘Add Selected’. Change the ‘Action’ from ‘Default’ to ‘Block’ and select ‘OK’.
- The signature appears under ‘IPS Signatures and Filters’ with 'Action = Block'. Select ‘OK’ to save.
