Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sveto
New Contributor

IPS FILTER

Dear all,

 

since I was not able to find answer to my simple question, I'm routing it here.

 

I'm configuring IPS Filter and I want it to log the packets only upon HIGH/CRITICAL severity events.

However, I want to keep my other Filter to work as usual without packet logging.

I'm just not sure, if IPS sensor is looking through all the filters or it will just hit the first match and bypass others. (This is the main question.)

 

1) Example (what I did, current config):

#1 High, Critical -> block, log the packet

#2 Protect client + some protocols, default, no packet log

 

2) Example (will make sense?):

#1 High, Critical -> monitor, log the packet

#2 Protect client + some protocols, default, no packet log

 

If you look at second scenario, I think the #1 filter will pass all the packets and #2 won't ever take action, Am I wrong? 

 

 

 

 

 

 

3 REPLIES 3
ssudhakar
Staff
Staff

Hi there:

 

FortiGate follows Top-Down approach in the table of IPS signatures and Filters to take appropriate action when there is a signature hit. 

 

Below is  a kb on how to configure IPS profile and an explanation on how it works 

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-Configure-the-FortiGate-to-Block-an...

 

Under IPS sensor configuration in GUI, ensure the selected signatures are arranged in proper order according to your need since FortiGate follows Top-Down approach in the table of IPS signatures and Filters to take appropriate action when there is a signature hit.

 

Hope that helps!!

 

Thank you,

Hope

Sveto

Thanks a lot !

ssudhakar

You are very welcome Sveto!! 

 

-/Hope

Labels
Top Kudoed Authors