Configuring intrusion detection
Security > Intrusion Detection lets you manually add IP addresses to be exempted from being blocked and configure intrusion detection settings.
The manually added IP addresses are usually from the sources that you trust. For example, IP addresses from external customer devices can be added.
IP addresses of the devices that are registered to the FortiVoice unit are automatically added to the exempt list.
For information on viewing system added exempt IPs, see Blocking SIP device IP addresses.
To add an exempt IP
- Go to Security > Intrusion Detection > Exempt IP.
- Click New.
- Enter the IP address or netmask of the network interface that you want to add to the exempt list.
- Click Create.
To configure intrusion detection settings
- Go to Security > Intrusion Detection > Setting.
- Configure the following:
GUI field
Description
Status
- Disable: Select to stop the intrusion detection activities.
- Monitor Only: Select to only track the intrusion detection activities.
- Enable: Select to activate the intrusion detection activities.
Access tracking
Select the method to track the traffic access (and IP addresses) to the FortiVoice unit.
Initial block period
Enter the time in minutes to initially block every new device/IP address trying to access the FortiVoice unit. This is to screen out spammers or attackers because they normally will not try again after being blocked initially.
- Click Apply.