Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
santonic
New Contributor

SCADA IPS signatures

How do I get SCADA signatures to my device?

 

In FortiGuard (https://fortiguard.com/encyclopedia) i can find some SCADA related IPS signatures.

But on my device I can't find any. I have IPS updated to the laest version and "Use extended IPS signature package" enabled.

 

What am I missing?

 

 

4 REPLIES 4
pcraponi
Contributor II

Hi,

 

[Using FortiOS 5.2.8] Menu: Security Profiles -> Intrusion Protection -> edit some profile -> on Filter Options click on ADVANCED -> On the new Application menu click on [Show more...] -> you will see "SCADA" filter. Disable all and let only SCADA to see the signatures.

 

Regards

Paulo R.

 

Regards, Paulo Raponi

Regards, Paulo Raponi
santonic

Thank you for your answer. But on FortiOS 5.4.1 i can't find these filter options and 'advanced' option.

 

When I am editing IPS profiles i have sections "IPS signatures" (to add/change individual signatures) and "IPS Filters" (to work with filters). But when I try adding filter I have no 'advanced' option. If I chose modbus as protocol i have no signature, if i choose SCADA as application i have 2 signatures (both without SCADA string in name). While on FortiGuard list i can find about 30 signatures.

 

pcraponi

Create a new Filter inside the Profile. On Filter Edit, click on Add Filter and Application. Now you will see SCADA with 154 signatures:

 

https://s31.postimg.org/uddldc6ij/scada.jpg

 

Regards,

Paulo R.

 

Regards, Paulo Raponi

Regards, Paulo Raponi
tom1o
New Contributor

Update FortiOS Update latest Next Gen. signatures

 

Im  using Forti OS 5.2 and i got signatures from 104 channel which a Scada function is in my appliance.

Labels
Top Kudoed Authors