Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
marypoppins
New Contributor II

Predefined IPS signature settings

Dear All,

 

 

Could you please tell me how can I view the settings (F-SBID) of predefined ips signatures? Also where can I modify the rate/limit setting for example for the SMTP.Login.Brute.Force ? Especially in CLI?

Thank you

 

fortigate 600e

1 Solution
pminarik

It's the same in 6.4 and 7.0/7.2. If you're not too familiar with it, perhaps GUI will be easier. You need to pick the specific signature(s), and then switch "Rate-based settings" to "specify". Then you will be able to set the threshold and duration.

 

GUI IPS signature filter rate-based settingsGUI IPS signature filter rate-based settings

 

[ corrections always welcome ]

View solution in original post

4 REPLIES 4
gfleming
Staff
Staff

Here is the documentation to modify the rate-based settings: https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/419589/ips-configuration-opt...

 

Unfortunately I am fairly certain there is no way to view the F-SBID of the predefined IPS signatures. TAC can help you modify them as needed, though, on a case-by-case basis.

Cheers,
Graham
marypoppins

Sorry forgot to mention, version 6.4
I can not find its equivalent in the 6.4 version docs :(

pminarik

It's the same in 6.4 and 7.0/7.2. If you're not too familiar with it, perhaps GUI will be easier. You need to pick the specific signature(s), and then switch "Rate-based settings" to "specify". Then you will be able to set the threshold and duration.

 

GUI IPS signature filter rate-based settingsGUI IPS signature filter rate-based settings

 

[ corrections always welcome ]
marypoppins

Ohh, I could not see the forest for the tree! And it also obvious in cli now.

Thank you

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors