Hi, new on the forums and fairly new to Fortigate.
So...
The default action on a lot of IPS signatures is Pass. But action Pass produces no logging!
I would like to at least log ALL hits to any signature.
Can this be done easily?
[ul]You can add two IPS filters, one for target client, one for target server, that's all signatures. Then set the action to monitor.
Or do it with every severity and for the high and critical set the action to block. This is just a task which takes a few minutes
As a sidenote: I keep IPS sensors separate for servers (IPS Sensor protect_servers) and clients (IPS Sensor protect_clients), based on target filter. Currently protect_servers blocks every.
Good suggestion about using severity. For protect_clients I could make a filter (target client + severity X) for each severity (5 levels).
You actually have to read my question in the context of me coming from a different firewall vendor: I would like to use the Default action for anything that does not have Pass for default action.
Although I realise that currently makes no sense: the only other default action Fortinet uses in the IPS database is Block (no actions Reset and Monitor).
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.