Description
This article describes One-Armed IDS/IPS configuration in FortiOS 4.0.
Solution
One-Armed IDS/IPS could only be configured through the command line in older FortiOS versions.
More recently, the option is also present in the GUI, under the interface in Network -> Interface > (select a physical interface) > 'Addressing mode': One-Arm Sniffer
The FortiGate unit could be in NAT or Transparent mode.
NOTE: This mode only generates logs/reports on specific traffic according to the applied profiles; it does not deny or influence traffic.
Once the interface mode is changed to One-Arm sniffer, several filters become available on the interface itself, but one can only use and edit the corresponding individual “sniffer-profile” of each of the security profiles applied.
Spam filter, DLP, and IPS DoS in this setup can only be configured through CLI:
# config system interfaceIf the option is not available, the interface is in use (by another policy, or referenced elsewhere in the configuration).
edit <port_name>
set ips-sniffer-mode enable
end
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.