Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
New Contributor III

Ips Action Default




Ips default action change from  block to monitor, why it is changing in the database also ? 


If I need two sensor, in one  I need to block  and the other one I need to monitor 

What is the default action in the signature database ? 



Valued Contributor

Default action of most of the signatures is PAss/Monitor, this is done by Fortinet to prevent false positives. Also, it may change per signature basis after an IPS update.

TO control the signature action use Signature Override, which was created exactly for that, such action will not be changed by updated to IPS.


Yuri blog: All things Fortinet, no ads.

All opinions are mine only.