FortiSigConverter management extension tool to import Snort rules 6.4.3
FortiManager supports Snort, a popular open source Network Intrusion Detection System (NIDS), using the FortiSigConverter application.
You can download FortiSigConverter from registery.fortinet.com
directly in FortiManager using the Management Extensions module.
To enable FortiSigConverter in the GUI:
- Go to Management Extensions.
- Click FortiSigConverter to download the management extension, and then open the application.
The FortiSigConverter dashboard is displayed.
- To import a signature file, click Import SNORT Signature, and click OK.
- Click OK to confirm the import.
The signatures are added to the signatures list.
- To push Snort rules to FortiManager, open a signature file and select the rules you want to push.
- Click Push to FortiManager, and click OK.
- Click OK in the dialog box to complete the process.
To view IPS signatures in FortiManager:
- In FortiManager, go to Policy & Objects > Object Configuration.
- Click Tools > Display Options.
- In the Security Profiles module , select Enable IPS Custom Signature.
- To view the signatures, go to Security Profiles > IPS Signatures.
To enable FortiSigConverter in the CLI:
config system docker
set fortisigconverter enable
end