Hi guys,
I wonder if enabling IPS in the direction LAN --> WAN is necessary or not in order to protect my PCs againts attacks. I mean enabling IPS from LAN to Internet, like this:
Is it ok?
Regards,
Julián
Solved! Go to Solution.
The short answer is yes. Enabling IPS on the outbound policy should protect the sessions that are initiated by that policy. in general you should not have a wan --> lan policy.
Correct. As long as your wan --> lan policy is just for the VIPs and has its own protection profiles that should be fine.
BTW, if as part of your WAN --> LAN rules you have a DENY policy that involves VIPs, you should check that it has match-vip enable. Otherwise it is possible that those rules won't be matched. http://socpuppet.blogspot.com/2016/02/this-is-reminder-for-set-match-vip.html
Que le vaya bien.
The short answer is yes. Enabling IPS on the outbound policy should protect the sessions that are initiated by that policy. in general you should not have a wan --> lan policy.
Hi tanr,
Ok, thank you. I also have enabled IPS in a WAN --> LAN policy in order to protect the customer servers, because the customer is using Virtual IPs and Destination NAT to access some servers remotely. I just wanted to be sure because some collegues told me that I only needed enable the IPS in the WAN --> LAN direction and not in the LAN --> WAN direction. Then I wondered, how will I protect the hosts againts attacks initiated from outside? And as you told, enabling IPS on the outbound policy should protect the sessions that are initiated by that policy (therefore by the hosts).
Many thanks!
Julián
Correct. As long as your wan --> lan policy is just for the VIPs and has its own protection profiles that should be fine.
BTW, if as part of your WAN --> LAN rules you have a DENY policy that involves VIPs, you should check that it has match-vip enable. Otherwise it is possible that those rules won't be matched. http://socpuppet.blogspot.com/2016/02/this-is-reminder-for-set-match-vip.html
Que le vaya bien.
Ok, thanks for the reminder and your interest!
Regards,
Julián
User | Count |
---|---|
2270 | |
1232 | |
772 | |
452 | |
396 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.