Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
generaltab
New Contributor

What to do with IPS?

Why are certain anomalies, such as udp_flood, disabled by default? It' s default action is pass, as well. Also, the sample " strict" protection profile enabled protection from only critical anomalies. I' m having a hard time getting a handle of IPS. Should my profile protect against all enabled signatures and anomalies above a certain severity? Which shall I enable? What level of severity? Thanks!
3 REPLIES 3
Not applicable

http://support.fortinet.com/forum/tm.asp?m=19602&p=1&tmode=1&smode=1
Not applicable

Im with you- running the Wizard or just using the strict settings to think you are getting the top protection with minimal configuation will not be optimal. i am trying to figure why i get periods where things are great, then many " page not found" erros in IE. I unchecked all but critical and high in IPS, and the problem is gone. however, that doesnt mean my security is set optimally. so, i got a lot of reading to do. i might just pay already for a setup and monitoring service.
Not applicable

Out of curiousity, did you manage to outsource your FortiGate setup and monitoring functions?
Labels
Top Kudoed Authors