FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ppatel
Staff
Staff
Article Id 208016
Description

This article describes that CLI attributes for custom signatures are ignored in 6.2 and later versions.

Scope

FortiGate v6.2, v6.4, v7.0, v7.2, v7.4 and v7.6.

Solution

Creating a custom signature as follows:

 

config ips custom
    edit "test_signature"

        set signature "F-SBID( --attack_id 8888; --name test_signature;)

        set severity low    <----- Define severity.

        set location server <----- Can be 'client' or 'server'.

        set status disable  <----- Can be 'enable' or 'disable'.

        set comment "test"

    next

end

 

The 'status', 'location', and 'severity' CLI attributes are not used anymore and will have no effect.

The status will remain default 'enable' and severity 'critical'.

 

The severity can be only defined in the signature syntax with the '--severity' statement.