Running a 100D on 5.2.2, just updated to 5.2.3. I have IPS rules setup to quarantine IPs but they stopped working about two weeks ago. I thought updating to 5.2.3 might fix but I'm not see any IPs that trigger IPS rules set to quarantine being added to the list.
The other issue I had was with updated IPS definitions being added to existing lists. The:
MS.Windows.HTTP.sys.Request.Handling.Remote.Code.Execution
vuln is pretty serious and we had one server that should have been protected by that signature have an attempted exploit launched at it. An upstream MSP detected the attempt. So when I checked on the IPS sigs my Fortinet was enforcing for that connection; despite me having selected "Server" and "Windows" for the criteria, this IPS sig was not enabled.
It appears it falls under the "Server", "Windows", and "Other" for Application. But if you enable "Other" the filter pulls all sorts of stuff like AOL that doesn't apply to my server. If someone can explain the logic behind how the IPS sigs are selected based on categories selected, that would be great.
Wondering if anyone else has seen these issues.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Let's go back to the quarantine or lack of, are you sure the sensor is still applied to the policy and the traffic is matching that policy? & the action is quarantine ?
I know others have had issues with policies ( not me ) when upgrading but I would check that and any ordering. Maybe generating some traffic to cause the sensor to match and diag debug flow my shed some light on this problem.
FWIWl I spent 2 days ago with a client of mine who disabled a fwpolicy & I only found the issues after he grant us remote access, so make sure the policy was not set status disable
next, can you explain better on the last problem? I'm not quite following you.
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.