Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Default Action - Pass?
I' m not sure if I am misreading things, but it seems that a lot of " Critical" severity IPS events listed in the " Predefined" tab have a default action of " Pass" . Why is this? Is Fortinet just being overly cautious in terms of usability, or am I missing something?
----------------(--
Jeff
----------------(-- Jeff
4 REPLIES 4
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe those IPS signatures doesn' t apply to a one widely deployed network.
If IPS apply to a very specific traffic or software that you don' t have in your network, why enable related signatures?
regards
/ Abel
regards
/ Abel
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am not talking about enabling. I am referring to the default " Action" parameter. Look up " MS.DirectX.MsVidCtl.ActiveX.Control.Access" for instance. It is the signature for the exploit publicized this week for Direct X exploit that can be used in normal web browsing. The severity level is considered " Critical" , but according to " Predefined" tab, packets utilizing this exploit will be passed by default, unless I specify that the IPS sensor it is enabled in overrides the default action value. My question is, if this exploit is considered " Critical" why isn' t the default action " Drop" ?
----------------(--
Jeff
----------------(-- Jeff
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
you have to tweak and adjust each signature. I think all are set to pass by default. Since fortinet doesn' t know " your" network and systems, the default is to pass.
PCNSE
NSE
StrongSwan
PCNSE
NSE
StrongSwan
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the default action for most signatures is set to pass, because false positives can occur. IPS should not interfere with normal traffic.
You have to tune the IPS settings according to your network. Of course this is a time consuming task which is neglected quite often.
