Fortinet white logo
Fortinet white logo

Botnet C&C signature blocking

Botnet C&C signature blocking

To add IPS signatures to a sensor using the GUI:
Note

One option is to use a predefined default IPS profile to block C&C Signatures. Default IPS profile is pre-configured with default action(block) for severity level 3, 4 and 5 which covers all the C&C signatures.

  1. Go to Security Profiles > Intrusion Prevention.
  2. Edit an existing sensor, or create a new one.
  3. In the IPS Signatures and Filters section, click Create New.
  4. Set Type to Signature.
  5. Enter botnet in the Search field to get the list of all available signatures from the database.
  6. Right-click the signatures you want to include from the list.
  7. Click Add Selected.
  8. Configure the other settings as required.

  9. Click OK
  10. Configure other settings as required, then click OK
  11. Add this sensor to a firewall policy to detect or block attacks that match the IPS signatures.

Botnet C&C signature blocking

Botnet C&C signature blocking

To add IPS signatures to a sensor using the GUI:
Note

One option is to use a predefined default IPS profile to block C&C Signatures. Default IPS profile is pre-configured with default action(block) for severity level 3, 4 and 5 which covers all the C&C signatures.

  1. Go to Security Profiles > Intrusion Prevention.
  2. Edit an existing sensor, or create a new one.
  3. In the IPS Signatures and Filters section, click Create New.
  4. Set Type to Signature.
  5. Enter botnet in the Search field to get the list of all available signatures from the database.
  6. Right-click the signatures you want to include from the list.
  7. Click Add Selected.
  8. Configure the other settings as required.

  9. Click OK
  10. Configure other settings as required, then click OK
  11. Add this sensor to a firewall policy to detect or block attacks that match the IPS signatures.