Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ian_Harrison
New Contributor

IPS - do you use it on incoming only or outgoing as well

Hi

 

The connections to our internal sites are checked by IPS rules I just wondered does anyone apply IPS checking to outbound traffic as well such as user web browsing etc.  I know that the IPS puts a load on the Firewall so want to know what other people did as well.

 

Thanks for any info.

 

Ian

Web: www.activatelearning.ac.uk Twitter: twitter.com/activate_learn Facebook: facebook.com/Activate-Learning
4 REPLIES 4
ponder
New Contributor III

I think outbound you would apply DLP rules ?

 

Can't say I use it though.

emnoc
Esteemed Contributor III

I hate to  use in or out going but rather use "protect server" or "protect client", with that said most establishment proper use both and even dual tiered ( external IDS/IPS  sensor + internal IDS/IPS sensor )

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
razor
New Contributor III

Incoming only. I create my own IPS rules to protect the users against the latest threats. (Snort rules can be used!:) )

Fortinet Network Security Professional (NSE4)

Fortinet Network Security Professional (NSE4)
ede_pfau

If you control guest access to the Net IPS on outgoing traffic is valuable. I use a rate-limited sensor to block excess mail sending (SMTP) to mediate SPAM outbreaks. Sender will be quarantined for 24 hours (or for good) if sending more than 100 emails per minute.

Otherwise, if undetected the ISP will blacklist the mailserver for days at least, with desastrious consequences.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors