Hi,
I'm trying to figure out what the best generic ips signatures might be to add for traffic going to the outside. I was thinking maybe of signatures like Generic.DNS.tunnel.detection.variant.A or similar ...
Anyone have any ideas on which ones might be the best?
Thanks
Created on 02-24-2022 12:58 PM
Hello @DanieleS99 ,
Thank you for posting to the Fortinet Community.
As per your query you can enable the IPS filter with the severity level as Medium, High or Critical which can be used with default actions.
You can use the link mentioned below for your configuration.
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/48143/intrusion-prevention-system-ips
Let me know if this helps.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.