Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tobisfr
New Contributor III

IDS / IPS between internal VLANS

Hi,

 

is anyone here using IDS/IPS to secure interlan LANs (VLANS) for example:

 

CLIENT VLAN to Server VLAN   = IDS Protect Server

CLIENT VLAN1 to Client VLAN2 = IDS Protect Client

 

I would like to get some experience if it works good und make sense?

We are routing our internal VLANs with the Fortigate.

 

Regards

Tobi

3 REPLIES 3
Markus
Valued Contributor

Hi, Thats a good question. We do IDP/IDS between Client and Server VLAN. I think it depends on your environment. We have a open policy, all Notebooks can also be used at home and any user is able to install stuff. Thats why I have enabled IDS and AV between the VLANs. I'm wondering what the community means, make sense? Best


________________________________________________________
--- NSE 4 ---
________________________________________________________

________________________________________________________--- NSE 4 ---________________________________________________________
tobisfr
New Contributor III

So long time ago an still the same question? How to use IDS/IPS correctly to secure communication in the internal network?
ede_pfau

'correct' is a strong word. No two networks are identical.

 

Only one thing to ponder:

if you apply IPS to client traffic load on the FGT will increase, sometimes substantially. But it's effective nonetheless - these days I cut off a client machine using bad, bad proxying (trying to circumvent the firewall??) by applying my default 'no proxy' IPS settings. Just to discover my client had installed a company proxy server, without communicating this.

Segmenting the LAN in VLANs for functional groups (like servers) is a good practice. Securing the server VLAN may just be enough for many installations.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors