Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rob_cart
New Contributor

SSL VPN Portal IPS Sensor

I' m wondering if anyone applies IPS protection to the policy that enables the SSL VPN portal to work ? I have created custom IPS profiles to protect say Microsoft web servers in my network but should i have create an IPS profile to protect the SSL VPN portal ? I would say it would be a good thing to do but as I' m not exactly sure what platforms are running here i.e i' m assuming linux OS ? Apache web server ? Any ideas or experience would be much appreciated ! Cheers Rob
11 REPLIES 11
netmin

Afaik, an interface policy did/does not perform deep inspection on SSL traffic and malicious hb request detection is a tls record layer pattern matching ips signature, isn' t it? I think it is worth, at least to us, following up on / evaluating the VIP->loopback variant, as already used by AtiT, also to present the portal on a different IP.
FortiAdam

Well it was the official work around that Fortinet posted so I hope it was sufficient. I confirmed via multiple methods that the SSL VPN portal was no longer vulnerable to heartbleed after applying the interface policy with the appropriate IPS sensor. At the bottom of the page here is where you can find a brief mention of this: http://www.fortiguard.com/advisory/FG-IR-14-011/
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors