FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
mle2802
Staff
Staff
Article Id 349408
Description This article describes how to find missing IPS signatures from the database.
Scope FortiGate.
Solution When finding the IPS signature under Security Profiles -> IPS Signature, the signature cannot be found. In this case, using signature 'HTTP2.RST_STREAM.Rapid.Reset.CVE-2023-44487.DoS' as example:

ips_sig.png
However, when verifying the signature from the FortiGuard website using the following link IPS signature, it is stated that the signature is added to both regular and extended databases.

This can happen because there is no IPS profile referenced under any firewall policy and the database is not updated. Enable the IPS profile under one of the firewall policies and run the command 'execute update-now' to update the database.
Related Article: How to update IPS signatures at FortiGate when there are less signatures.

policy+ips.png
updated ips.png