A real-life situation
WEB1 is now reachable from the Internet, and within hours its logs fill with scans for well-known web application exploits. Meanwhile a staff member downloads an invoice that is really malware. FGT1 already allows both sessions; antivirus and IPS decide whether the content inside them gets through.
Antivirus
Edit AntiVirus Profile: default
- Feature set
- Flow-based Proxy-based
- Protocols
- HTTP SMTP POP3 IMAP FTP CIFS
- Use FortiGuard outbreak prevention database
- On
- Treat Windows executables in email attachments as viruses
- Off
Inspected Protocols
APT Protection Options
- Infected files are blocked and the user sees a replacement page instead; the event is logged with the virus name.
- HTTPS downloads are only scanned with deep inspection.
- Very large files, or archives too deep to unpack, are handled by oversize settings (pass or block); know which your profile uses.
IPS sensors
An IPS sensor selects signatures with filters (severity, target client or server, operating system, protocol) and sets an action for them. Built-in sensors cover the common cases:
| Sensor | Use on |
|---|---|
| default | General traffic: critical, high and medium severity signatures |
| protect_client | Outbound policies: attacks against users' browsers and apps |
| protect_http_server | Inbound policies to web servers, such as Internet-to-WEB1 |
| high_security | Strict environments: blocks more signatures, more false positives |
config firewall policy
edit 3
set ips-sensor "protect_client"
set av-profile "default"
next
edit 6
set ips-sensor "protect_http_server"
set ssl-ssh-profile "WEB1-inbound"
next
endPolicy 3 (LAN-to-Internet) protects users; policy 6 (Internet-to-WEB1) protects the server. WEB1-inbound is an SSL inspection profile with WEB1's own certificate, so IPS can see attacks inside HTTPS.
IPS also includes rate-based signatures (for brute-force and flood patterns) and a botnet option that blocks connections to known command-and-control servers.
Testing safely
- Antivirus: download the EICAR test file from a trusted source over HTTP (and over HTTPS once deep inspection is on). It is a harmless text string that all scanners detect by agreement.
- IPS: check Log & Report › Security Events › Intrusion Prevention after a vulnerability scan of WEB1 that you have permission to run.
- Never test with real malware.
Are the signatures current?
diagnose autoupdate versions lists the AV and IPS engine and database versions and when they last updated; System › FortiGuard shows the licences. Outdated signatures are almost as bad as none.
Why it works this way
Attacks travel inside allowed traffic: malware in a normal-looking download, exploits in normal-looking web requests. Only content inspection can see them, and only signatures that are current can recognise them. Choosing IPS signatures by target keeps inspection relevant: a web server doesn't need browser-exploit signatures, and a laptop doesn't need server-side ones.
Common mistakes
- Putting a server-protection sensor on outbound user traffic, or the other way round.
- Forgetting that encrypted traffic needs inspection for AV and IPS to work.
- Letting the FortiGuard licence lapse.
- Testing with live malware instead of EICAR.
Key takeaways
- Antivirus scans files in web, mail and file transfers; IPS matches exploit and attack signatures.
- IPS sensors select signatures by filters; built-in sensors suit clients and servers.
- Inbound HTTPS to your server can be inspected with its own certificate.
- Test with EICAR and scans you are allowed to run; check signature versions regularly.
Check yourself
Which IPS sensor belongs on the Internet-to-WEB1 policy?
How do you check antivirus detection without risking a real infection?
An attack against WEB1 inside HTTPS isn't detected by IPS. What is needed?