Skip to main content
fjulianom
Explorer II
July 20, 2018
Solved

How to protect clients and servers with IPS?

  • July 20, 2018
  • 3 replies
  • 8419 views

Hi guys,

 

I have a FortiGate and three firewall policies: one for the communication from clients (laptops) to servers, one for the communication from servers to clients, and one for Internet access from clients to Internet:

 

Clients --> Servers

Servers --> Clients

Clients --> Internet

 

I have configured two IPS profiles for protecting clients (target: client) and servers (target: server), called "protect_client" and "protect_server" respectively.

What IPS profiles I have to use in each policy?

 

Regards,

Julián

    Best answer by Dave_Hall

    Generally, you will want to place an IPS sensor (profile) on traffic originating from internal to WAN (or your internet - e.g. client browsing) - if you have servers facing or accessing the Internet you will want to apply an IPS sensor to that traffic too (e.g. internal server -> WAN (or Internet). 

     

    Generally, in my personal experience I have never seen IPS applied to internal traffic communications, - usually server/client computers have (or should have) security/firewall mechanisms in place to prevent or log such incidents. And if I have any say in the matter, I rather see all outside mobile devices blocked from accessing your internal network.

     

    Also keep in mind too, that IPS (and other security policies) on the Fortigate can only be applied to traffic crossing a "interface" (e.g. LAN->WAN, WAN->LAN, LAN->DMZ, etc.). 

     

     

    3 replies

    fjulianom
    fjulianomAuthor
    Explorer II
    July 23, 2018

    Hi guys,

     

    Any idea?

     

    Regards,

    Julián

    Dave_Hall
    Dave_HallAnswer
    New Member
    July 23, 2018

    Generally, you will want to place an IPS sensor (profile) on traffic originating from internal to WAN (or your internet - e.g. client browsing) - if you have servers facing or accessing the Internet you will want to apply an IPS sensor to that traffic too (e.g. internal server -> WAN (or Internet). 

     

    Generally, in my personal experience I have never seen IPS applied to internal traffic communications, - usually server/client computers have (or should have) security/firewall mechanisms in place to prevent or log such incidents. And if I have any say in the matter, I rather see all outside mobile devices blocked from accessing your internal network.

     

    Also keep in mind too, that IPS (and other security policies) on the Fortigate can only be applied to traffic crossing a "interface" (e.g. LAN->WAN, WAN->LAN, LAN->DMZ, etc.). 

     

     

    fjulianom
    fjulianomAuthor
    Explorer II
    July 23, 2018

    Hi Dave,

     

    Thanks for your interest. When you say "Generally, in my personal experience I have never seen IPS applied to internal traffic communications, - usually server/client computers have (or should have) security/firewall mechanisms in place to prevent or log such incidents.". But does that mean that the built-in security/firewall mechanisms of servers/clients work well for only internal communications but not from WAN to LAN?

     

    Regards,

    Julián

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!