Skip to main content
FortiSpain
Explorer
January 18, 2026
Question

IPS Signatures

  • January 18, 2026
  • 18 replies
  • 1354 views

Hi,

 

We owe a Fortinet Fortigate 50G in a domestic environment. In the section "IPS Signatures", we can see more than 5864 entries. 84% is blocked but 16% shows "pass":

 

Here you have a few examples:

 

 

 

Does this mean a risk for our installation? Would it be better to have them all marked as "Block"? If positive, how can I change the action?

 

Thank you

 

18 replies

mpapisetty
Staff
Staff
January 18, 2026

Hi @FortiSpain,

Couple of things here - 

1. If you are seeing only 5864 IPS signatures, chances are that these came by default and never got updated. Hence, all the signatures would be stale and so the network is not protected. (The signature package is from 2015, more then 10 years old!)

2. The default action set by FortiGuard works fine for most cases. If there are some signatures in pass, it may mean little to no risk, or it is a new signature that will get updated soon. For instance, in the screenshot, I see "phpMyAdmin.Serversync.php.Backdoor" which is set to pass. As of today, the default action should be drop. Here is the link to the signature - https://www.fortiguard.com/encyclopedia/ips/33351 . As you can see, the signature got an update in 2017 which is not reflected in your screenshot as the IPS package you are running is very old. 

 

Unless you have a policy with IPS enabled on the firewall and with a valid support contract for UTM, you will not see any updates on the package. 

 

Hope this information helps. 

FortiSpain
Explorer
January 19, 2026

Hi @mpapisetty 

 

Thank you very much for your clear reply.

 

Could you be so kind as to answer the following question, please?

 

How is it possible to have such an old IPS package when the FortiGate is new?

How can I turn all the "pass" settings to "drop/block"?

 

I guess that UTM means "Unified Threat Management". The fact is that we have hired 1 year FortiCare Premium and FortiGuard UTP (United Threat)... So, the list should be updated (at least, by the company who installed the firewall), right?

 

Thanks again

mpapisetty
Staff
Staff
January 20, 2026

Hi @FortiSpain ,

Here are the answers - 

1. What you are seeing is the "default" package. The updates only happen through FortiGuard on devices with a valid contract. 

2. If you have a valid license/contract, yes. 

 

Here is a troubleshooting document that can help with the updates - https://community.fortinet.com/t5/FortiGate/Technical-Tip-Verifying-and-troubleshooting-FortiGuard-updates/ta-p/194931

FortiSpain
Explorer
January 22, 2026

... I have added "all" in "Service"

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!