IPS signatures categories confusion
Dear All,
I would like to make different ips security policies for different services (accepted by the appropriate firewall policies), however I have a confusion with signature categories. First I thought that for the https web services it is enough to make an ips sensor that includes the https from the protocol entries when editing the signatures filter, but I found something strange.
Before when I used an ips policy including every signatures I found a line in my fortianalyzer, that shows "action:dropped, service:HTTPS, attack name: Bladabindi.Botnet". Then I checked this attack name in fortigate ips signatures and in the protocol section it only shows TCP, but not HTTPS. I think this means if I only add the HTTPS protocols to my custom ips filter, this attack is not checked.
My question how should I make custom ips sensors for different protocols (an ips for http, an other to all email protocols) in order to not leave out any relevant signatures?
thank you
chr
