Detect/Dropped vs Passthrough
This might be a n00b question, but I just want to make sure I understand Fortigate processes traffic and alerts.
In the Fortianalyzer/Fortiview/Logs:
So, when I research an alert for Angler EK and I check the IPS logs, I see "detected" and usually "dropped" for a given IP, but when I search for the IP in the Web Filters and the "action" says "passthrough".
My question is, did the Fortigate allow the website requests from the IP and then when it detects Angler, the IPS then blocks the traffic? Or am I missing something?
I just want to know that if I see alerts on a particular EK like Angler or Nuclear and I check and see detected and dropped that there is no more action I need to take, like remediation, etc...
Thanks all,
MikeJ
