Skip to main content
mhaneke
Explorer III
February 4, 2026
Question

Fortigate 7.4 IPS - Allow known threat within an IPS rule

  • February 4, 2026
  • 1 reply
  • 134 views

Hello,

 

we have an application which uses a HTTP method in a way which is known to be a threat as of FortiGuard https://fortiguard.fortinet.com/encyclopedia/ips/12351 

I´d like to workaround this an although still blocking threats with severity medium high critical, I´d like to allow that special "HTTP.Server.Authorization.Buffer.Overflow" method, which is know as IPS rule 12351. The rules severity is high and the default action is "block". I tried to override this.

But the following rule does not work. Has anybody a suggestion why or what I could have done better?

 

config ips sensor

edit "protect-workararound"
set block-malicious-url enable
set scan-botnet-connections block
config entries

edit 1
set rule 12351
set status enable
set log disable
set action pass

end

next

edit 2

set severity medium high critical
next

end

next

end

 

best regards

Martin

 

1 reply

funkylicious
SuperUser
SuperUser
February 4, 2026

hi,

it should do the trick.

is the ips profile attached to the firewall in question? in the logs can you see the firewall policy and ips name that blocks it? maybe its hitting something else.

"jack of all trades, master of none"
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!