FortiGate Firewall: Intrusion Prevention System (IPS) Tutorial

  Рет қаралды 10,596

FortiBytes

FortiBytes

Күн бұрын

Пікірлер: 24
@DemeterN
@DemeterN 9 ай бұрын
Fantastic....this makes me so excited to explore further and explains in a very understandable way "how things work with Fortigate"
@FortiBytes
@FortiBytes 9 ай бұрын
Your very welcome lots of videos on the channel and it’s not going to stop! Let me know if there is anything specific you would like!
@RowanKaag
@RowanKaag 7 ай бұрын
Very helpful examples!
@WinfreySharon
@WinfreySharon 9 ай бұрын
Thank you. that was very clear and very helpful!
@FortiBytes
@FortiBytes 9 ай бұрын
You’re very welcome, checkout some of the other videos there is like 50 or something now. The FortiManager series in particular is recommended.
@clivethompson6546
@clivethompson6546 5 ай бұрын
Very helpful video, nice and clear, thanks.
@FortiBytes
@FortiBytes 5 ай бұрын
Glad it was helpful! Your Welcome!
@dgilvani
@dgilvani 4 ай бұрын
Golden! Thank you 😊
@FortiBytes
@FortiBytes 4 ай бұрын
You’re welcome, more videos soon.
@ornaldonaqellari1254
@ornaldonaqellari1254 4 ай бұрын
Thank you for the video. I do have a question: Why in the case of internal traffic leaving to internet we need to apply even the IPS Signatures and Filters ? Is it just enough to enable Block Malicious URLs and Outgoing Connections to Botnet Sites ? so you can save memory and cpu ?
@FortiBytes
@FortiBytes 4 ай бұрын
Hey, great question and its something that comes up quite frequency. IF you have the resources to do so then its best practice to apply IPS to outbound policys also. Sometimes malware gets inside your envrioment meaning that the traffic orginates from the inside lets use a TCP based reverse shell for example communicating back to a know C&K server.
@user-oj6iz2im4w
@user-oj6iz2im4w 3 ай бұрын
Good video. I just bought my fortigate and thought it was protecting me but it wasn't.
@FortiBytes
@FortiBytes 3 ай бұрын
Make sure you look into some of the other videos on the channel, specially deep packet inspection as most of the traffic going through your device is encrypted so you need some additional steps to be able see into that traffic.
@user-oj6iz2im4w
@user-oj6iz2im4w 3 ай бұрын
@@FortiBytes thanks, I had enabled everything but had to back it down due to certificate warnings
@rogergaudet9786
@rogergaudet9786 Жыл бұрын
Just to get a clarification, if for example, I am protecting a DNS server in an inter-VLAN scenario and I create a filtered IPS sensor like you described, there is no reason to enable deep packet inspection on the policy if all I have is port 53 allowed in the policy since I'm not doing DNS over TLS, correct?
@FortiBytes
@FortiBytes Жыл бұрын
Yes this is correct if your only limiting to DNS meaning all other potential exploits that might be wrapped inside tls/ssl are mitigated only leaving things specific to dns like reflection attacks. I’ll be honest I wanted to expand more on this whole deep packet discussion but the video had already massively overran! I’ll be doing a video at some point specially around deep packet inspection. There are clients out there such as programmable logic controllers in the OT space where you cannot even install a certificate to be able to do it! Thanks for reaching out!
@sn3aky-t217
@sn3aky-t217 Жыл бұрын
@@FortiBytes I would love to see a video about SSL deep inspection. I notice a lot of companies struggle with it and because of the impact it gives, they are not using it. Causing blind spots. I hope you can do a video that also explains how to deal with apps/websites that don't like SSL deep inspection and also what are like the basic design/implementation routes you take before turning it on and causing a big bang.
@FortiBytes
@FortiBytes Жыл бұрын
​@@sn3aky-t217Thanks for reaching out Its the next video I'm doing! (I promise). Its a complex topic that's super important and I want to ensure I hit the spot with it. The videos I have been releasing this week and the one tonight are leading up to it!
@simonbell3619
@simonbell3619 Жыл бұрын
audio much better, much louder and clearer
@FortiBytes
@FortiBytes Жыл бұрын
Thanks Si
@sn3aky-t217
@sn3aky-t217 Жыл бұрын
Yes it's much better. Huge improvement. Really enjoy the videos. Maybe for the future you could check if you could place some items that reduce the echo-ing. I think you could fabricate something with curtains/rug/pillows/whatever before you go and purchase all these expensive sound panels.
@FortiBytes
@FortiBytes Жыл бұрын
@@sn3aky-t217 I’m sat in the sound proofed room that’s designed to keep the sound inside! So it’s working against what we need here! I’m going to get some of that foamy stuff and plaster it all over the walls at some point! Thank you for the awesome feedback also!
@SuperDaddyof2DD
@SuperDaddyof2DD Жыл бұрын
a lot of discussion prior to showing the actual tutorial, and then when showing how to create the sensor you gloss over how you actually created the sensor. I would prefer less discussion in the beginning, and a more exact route to create the sensor.
@FortiBytes
@FortiBytes Жыл бұрын
Hi 👋 ok no problem I’ll try and do more to the point technical stuff in future. Thanks for taking the time to feedback.
IDS vs IPS: Which to Use and When
5:39
CBT Nuggets
Рет қаралды 42 М.
Dad Makes Daughter Clean Up Spilled Chips #shorts
00:16
Fabiosa Stories
Рет қаралды 8 МЛН
He bought this so I can drive too🥹😭 #tiktok #elsarca
00:22
Elsa Arca
Рет қаралды 48 МЛН
Will A Guitar Boat Hold My Weight?
00:20
MrBeast
Рет қаралды 161 МЛН
An Unknown Ending💪
00:49
ISSEI / いっせい
Рет қаралды 12 МЛН
How to know if your PC is hacked? Suspicious Network Activity 101
10:19
The PC Security Channel
Рет қаралды 1,3 МЛН
FortiGate 80F Firewall Unbox and Configure
14:08
SinaOnline
Рет қаралды 7 М.
FortiGate FortiOS 7.2.4 Walk Through
34:10
Fortinet Guru
Рет қаралды 18 М.
Suricata Home-Lab for IDS/IPS {Add in your Resume Now!}
18:05
Rajneesh Gupta
Рет қаралды 3,4 М.
Fortinet Intrusion Prevention System Lab FSL 11
19:24
Prashant Khanna
Рет қаралды 3 М.
Dad Makes Daughter Clean Up Spilled Chips #shorts
00:16
Fabiosa Stories
Рет қаралды 8 МЛН