Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Explain of Threshold at IPS

Hello Regards. i am new at Fortinet and i dont understand exactly the concept of " Threshold" and the behavior of Fortigate when a Threshold triggers the anomaly, if some body help me i will thanks so much. i need only a litle explain.... regards..
2 REPLIES 2
rwpatterson
Valued Contributor III

A very simple explanation. The Fortigate is capable of 100 packets per second. You set you error threshold to 10 packets per second. If 11 or more erroneous packets are seen by the Fortigate in one second, it will trigger an alarm. It does not matter if the Fortigate only sees 11 erroneous packet in that second, or 100 packets and 11 are bad. Same effect. The filter only looks at what it' s configured for, and counts packets per time frame. Hope that helped.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

thank you Bob... i undernstand better....
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors