FortiGate Firewall: Intrusion Prevention System (IPS) Tutorial

  Рет қаралды 13,433

FortiBytes

FortiBytes

Күн бұрын

Пікірлер: 24
@DemeterN
@DemeterN Жыл бұрын
Fantastic....this makes me so excited to explore further and explains in a very understandable way "how things work with Fortigate"
@FortiBytes
@FortiBytes Жыл бұрын
Your very welcome lots of videos on the channel and it’s not going to stop! Let me know if there is anything specific you would like!
@RowanKaag
@RowanKaag 10 ай бұрын
Very helpful examples!
@WinfreySharon
@WinfreySharon 11 ай бұрын
Thank you. that was very clear and very helpful!
@FortiBytes
@FortiBytes 11 ай бұрын
You’re very welcome, checkout some of the other videos there is like 50 or something now. The FortiManager series in particular is recommended.
@clivethompson6546
@clivethompson6546 8 ай бұрын
Very helpful video, nice and clear, thanks.
@FortiBytes
@FortiBytes 8 ай бұрын
Glad it was helpful! Your Welcome!
@dgilvani
@dgilvani 7 ай бұрын
Golden! Thank you 😊
@FortiBytes
@FortiBytes 7 ай бұрын
You’re welcome, more videos soon.
@rogergaudet9786
@rogergaudet9786 Жыл бұрын
Just to get a clarification, if for example, I am protecting a DNS server in an inter-VLAN scenario and I create a filtered IPS sensor like you described, there is no reason to enable deep packet inspection on the policy if all I have is port 53 allowed in the policy since I'm not doing DNS over TLS, correct?
@FortiBytes
@FortiBytes Жыл бұрын
Yes this is correct if your only limiting to DNS meaning all other potential exploits that might be wrapped inside tls/ssl are mitigated only leaving things specific to dns like reflection attacks. I’ll be honest I wanted to expand more on this whole deep packet discussion but the video had already massively overran! I’ll be doing a video at some point specially around deep packet inspection. There are clients out there such as programmable logic controllers in the OT space where you cannot even install a certificate to be able to do it! Thanks for reaching out!
@sn3aky-t217
@sn3aky-t217 Жыл бұрын
@@FortiBytes I would love to see a video about SSL deep inspection. I notice a lot of companies struggle with it and because of the impact it gives, they are not using it. Causing blind spots. I hope you can do a video that also explains how to deal with apps/websites that don't like SSL deep inspection and also what are like the basic design/implementation routes you take before turning it on and causing a big bang.
@FortiBytes
@FortiBytes Жыл бұрын
​@@sn3aky-t217Thanks for reaching out Its the next video I'm doing! (I promise). Its a complex topic that's super important and I want to ensure I hit the spot with it. The videos I have been releasing this week and the one tonight are leading up to it!
@ornaldonaqellari1254
@ornaldonaqellari1254 7 ай бұрын
Thank you for the video. I do have a question: Why in the case of internal traffic leaving to internet we need to apply even the IPS Signatures and Filters ? Is it just enough to enable Block Malicious URLs and Outgoing Connections to Botnet Sites ? so you can save memory and cpu ?
@FortiBytes
@FortiBytes 7 ай бұрын
Hey, great question and its something that comes up quite frequency. IF you have the resources to do so then its best practice to apply IPS to outbound policys also. Sometimes malware gets inside your envrioment meaning that the traffic orginates from the inside lets use a TCP based reverse shell for example communicating back to a know C&K server.
@roku22-c3v
@roku22-c3v 6 ай бұрын
Good video. I just bought my fortigate and thought it was protecting me but it wasn't.
@FortiBytes
@FortiBytes 6 ай бұрын
Make sure you look into some of the other videos on the channel, specially deep packet inspection as most of the traffic going through your device is encrypted so you need some additional steps to be able see into that traffic.
@roku22-c3v
@roku22-c3v 6 ай бұрын
@@FortiBytes thanks, I had enabled everything but had to back it down due to certificate warnings
@simonbell3619
@simonbell3619 Жыл бұрын
audio much better, much louder and clearer
@FortiBytes
@FortiBytes Жыл бұрын
Thanks Si
@sn3aky-t217
@sn3aky-t217 Жыл бұрын
Yes it's much better. Huge improvement. Really enjoy the videos. Maybe for the future you could check if you could place some items that reduce the echo-ing. I think you could fabricate something with curtains/rug/pillows/whatever before you go and purchase all these expensive sound panels.
@FortiBytes
@FortiBytes Жыл бұрын
@@sn3aky-t217 I’m sat in the sound proofed room that’s designed to keep the sound inside! So it’s working against what we need here! I’m going to get some of that foamy stuff and plaster it all over the walls at some point! Thank you for the awesome feedback also!
@SuperDaddyof2DD
@SuperDaddyof2DD Жыл бұрын
a lot of discussion prior to showing the actual tutorial, and then when showing how to create the sensor you gloss over how you actually created the sensor. I would prefer less discussion in the beginning, and a more exact route to create the sensor.
@FortiBytes
@FortiBytes Жыл бұрын
Hi 👋 ok no problem I’ll try and do more to the point technical stuff in future. Thanks for taking the time to feedback.
FortiWEB (Web Application Firewall) | Practical Demo
30:14
Nettech Cloud
Рет қаралды 1,4 М.
Мама у нас строгая
00:20
VAVAN
Рет қаралды 12 МЛН
Farmer narrowly escapes tiger attack
00:20
CTV News
Рет қаралды 13 МЛН
FortiGate Firewall: Life of a packet troubleshooting
8:05
FortiBytes
Рет қаралды 10 М.
IDS vs IPS: Which to Use and When
5:39
CBT Nuggets
Рет қаралды 45 М.
IDS vs IPS vs Firewall #networksecurity #firewall #IPS #IDS
6:02
Team IPwithease
Рет қаралды 75 М.
Using FortiManager Series: Adding the First FortiGate! PT2
11:03
FortiBytes
Рет қаралды 1,5 М.
1  Configurer l'IPS
18:55
FORTINET FIREWALL
Рет қаралды 1,6 М.
FortiGate 80F Firewall Unbox and Configure
14:08
SinaOnline
Рет қаралды 10 М.
SSLVPN  replaced by FortiGate with IPsec VPN
20:42
Techy-World
Рет қаралды 1,4 М.
Firewall - Fortinet - Intrusion Prevention System [IPS]
25:44
Maddy’s World
Рет қаралды 29 М.