Description | This article describes how to allow specific IPS app signatures in case other IPS alerts are needed. |
Scope | FortiGate all firmware. It is possible to allow IPS traffic in the IPS profile by changing the action of the profile. |
Solution |
To allow IPS signature traffic, it is first necessary to check log messages to find out more about the IPS log details, like IPS name, rule number, etc.
To check log details, go to Log & Report -> Intrusion Prevention, and select log entry and Details in the right corner.
In the Intrusion Prevention section take notes of:
Profile Name: EICAR
Open CLI and execute:
After allowing the traffic, when the user tries to navigate and download a test file. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.