Configuring an intrusion prevention profile
To configure an intrusion prevention profile:
- Go to Security > Firewall Objects.
- Select Intrusion Prevention Profile from the Security Profiles dropdown.
- Select Create or select an existing profile from the list and click Edit.
- In the form, enter the following information:
Settings
Guidelines
Name
Required. Enter a name for the IPS Sensor.
Comments
Enter comments about the IPS Sensor.
Block malicious URLs
Select to block malicious URLs.
Scan Outgoing Connections to Botnet Sites
Choose from the following options:
Block: Scan and block outgoing connections to botnet sites.
Disable: Disable scanning outgoing connections to botnet sites (default).
Monitor: Monitor outgoing connections to botnet sites.
- Click Create to add an IPS signature filter to the IPS sensor.
To edit an IPS signature filter, select an IPS signature filter from the list and then select Edit.
When editing an IPS signature filter, the fields are the same as when creating it.
Use the search box to look for an IPS signature filter.
- In the Create IPS Signature Filter form, enter the following information:
Settings
Guidelines
Type
Select either Filter (default) or Signature.
Note: When the Type is Signature, select signatures from the list.
Use the Search bar to look for a signature.
Action
Select one of the following actions:
Default (default)
Allow
Monitor
Block
Reset
Quarantine: Enter the duration of the quarantine, and click Save.
Packet Logging
Enable or disable packet logging.
Status
Enable, disable, or set the status as default.
Filter
Select Edit IPS Filter to edit an IPS filter, enter the following information as shown in Edit IPS Filter.
Alternatively, from the list, select a preconfigured IPS filter and click Save.
Use the Search bar to look for an IPS filter.
Edit IPS Filter
Severity
Select severity levels:
Critical
High
Medium
Low
Info
Target
Select one or both of client and server.
Protocol
Select protocols.
OS
Select OS:
bsd
Linux
MacOS
Other
Solaris
Windows
Application
Select applications.
- Click Save to save changes to the IPS filter.
- Click Save to save changes to the IPS signature filter.
- Click Save to save changes to the IPS sensor.