FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
mpapisetty
Staff
Staff
Article Id 365333
Description

This article describes how to view IPS signature details using FortiManager. There are times when security administrators must deep dive into a particular IPS alert to know why a signature got triggered. In such scenarios, viewing the IPS signature pattern is useful for identifying the issues at hand.

Scope FortiManager.
Solution
  1. Within any one ADOM, navigate to Policy & Objects -> Object Configurations -> Security Profiles -> Intrusion Prevention.  All the IPS profiles are listed on this page. 
  1. Edit the 'all_default' profile and select 'Create New'.

 

  1. In the 'Search...' box, input the name of the signature that is of interest and select the name to view the details. A sample signature is shown below:

 

The 'Signature Details' section is the actual IPS signature pattern that is used by FortiGate to match traffic. With this information, security administrators can make informed decisions about the IPS alerts and matching traffic. 

 

Related documents:

Signature-based defense

Technical Tip: How to configure custom IPS signature for a specific web site 

Contributors