Skip to main content
Alexis_G
New Member
September 17, 2020
Question

IPS filter on Policy ID with multiple protocols

  • September 17, 2020
  • 1 reply
  • 2238 views

Hi 

I have following question

Lets assume we have a firewall policy permitting Windows Active Directory Traffic (which resulst various TCP, UDP protocols).

Ifr for example I create an IPS filter containning these protocols , when requests reach firewall all traffic will be inspected by IPS filter for any protocols , OR 

example : if it is DNS traffic, only DNS replated IPS signatures will scan packets ?

 

Example: One IPS filter for DNS + LDAP, + NTP +ICMP

if for example I ping an IP address , by maching rule with this IPS filter, packet will be inspected for all protocols above or ICMP only ???

Thanks

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    September 17, 2020

    https://docs.fortinet.com/document/fortigate/6.2.0/parallel-path-processing-life-of-a-packet/86811/packet-flow-ingress-and-egress-fortigates-without-network-processor-offloading

    As in the flow diagram, it wouldn't look for UTM profiles, and then execute inspections, until the traffic matches a policy. If the matching policy doesn't have UTM configured, the inspection based on the profile never happens.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!