hi,
i have enabled the IPS default profile in all the policies, have in my am using FortiGate 1000C version (v5.4.6).
does this profile effect the performance of the FortiGate.
regards.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Yes of course.
On my FGT, there are 5533 IPS signatures in the package. The default IPS sensor leaves out those with 'Low' threat level but there are still thousands left.
It doesn't make sense to apply IPS to traffic which is not covered. For instance, if the policy only allows FTP then only IPS signatures for FTP vulnerabilities should be scanned. Same for client/server addresses, only one subset of signatures applies to each.
You should really create your own set of signatures and granular policies to only apply as much scanning as necessary. The IPS engine can have a substantial effect on the performance of the whole FGT.
Keep an eye on your memory usage, you don't want conservative mode...
IPS signatures are specific for protecting clients or servers (or both), apply only what is necessary.
Eg. IPS security profile "protect_clients" that is applied to rules where clients initiate traffic. Another IPS profile "protect_server" that is applied to rules letting traffic "in" to servers.
Mind tho: a server connecting to another server (eg web service) should be considered a client for that traffic !
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.