How do I get SCADA signatures to my device?
In FortiGuard (https://fortiguard.com/encyclopedia) i can find some SCADA related IPS signatures.
But on my device I can't find any. I have IPS updated to the laest version and "Use extended IPS signature package" enabled.
What am I missing?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
[Using FortiOS 5.2.8] Menu: Security Profiles -> Intrusion Protection -> edit some profile -> on Filter Options click on ADVANCED -> On the new Application menu click on [Show more...] -> you will see "SCADA" filter. Disable all and let only SCADA to see the signatures.
Regards
Paulo R.
Regards, Paulo Raponi
Thank you for your answer. But on FortiOS 5.4.1 i can't find these filter options and 'advanced' option.
When I am editing IPS profiles i have sections "IPS signatures" (to add/change individual signatures) and "IPS Filters" (to work with filters). But when I try adding filter I have no 'advanced' option. If I chose modbus as protocol i have no signature, if i choose SCADA as application i have 2 signatures (both without SCADA string in name). While on FortiGuard list i can find about 30 signatures.
Create a new Filter inside the Profile. On Filter Edit, click on Add Filter and Application. Now you will see SCADA with 154 signatures:
https://s31.postimg.org/uddldc6ij/scada.jpg
Regards,
Paulo R.
Regards, Paulo Raponi
Update FortiOS Update latest Next Gen. signatures
Im using Forti OS 5.2 and i got signatures from 104 channel which a Scada function is in my appliance.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.