入侵防御系统 (IPS)

功能强大、创新发展

FortiGate IPS — 再次获得 NSS Labs“推荐”评级
适用于:
  • 设备
  • 虚拟机

FortiGate IPS Overview

Whether part of a firewall solution or a separate standalone appliance, Intrusion Prevention Systems (IPS) technology is becoming an increasingly ubiquitous part of network security defenses. Fortinet, well known for its next-generation firewall (NGFW) solution, has built IPS technology for more than ten years. Fortinet customers expect and depend on high performance from FortiGate firewalls and FortiGate IPS benefits from this legacy, delivering pound-for-pound, the best IPS performance available in the market today. FortiGate IPS, following a different evolution path than traditional IPS, innovates in ways that other standalone IPS products do not.

 

FortiGate IPS Webinar and Videos

Breathe New Life Into Your IPS Strategy with Today’s Evolved Options

Breathe New Life Into Your IPS Strategy with Today’s Evolved Options

The true dilemma for most organizations facing today's sophisticated threats is which approach to IPS will meet their unique network needs.

Watch the recorded webinar

FortiGate IPS Product Details

Zero-day, advanced targeted attacks, ransomware, polymorphic malware and distributed denial-of-service attacks all require sophisticated detection engines not available in traditional standalone IPS or in most firewalls. FortiGate IPS includes multiple inspection engines, threat intelligence feeds and advanced threat protection options to defend against these unknown threats. Packaged in powerful FortiGate platforms (hardware, virtual, cloud) with advanced analytics and workflows through FortiAnalyzer, FortiGate IPS is a cost-effective network security solution to feed incident response needs in your SOC.

 

Features and Benefits

 

checkmark icon

World-class Protection

Deep inspection for advanced threats, botnets, zero days and targeted attacks on the network
top rate icon

Industry certification

Independent third-party validation to demonstrate superior detection and best price performance
icon benefits spu

High performance

Innovative security processor (SPU) technology for high-performance network throughput and deep security inspection
icon sandbox

Advanced threat protection

Seamless integration – appliance or cloud service – with world-class sandboxing for advanced threats
Icon security fabric

Security Fabric integration

Integration and automation with Fortinet’s broad product portfolio and partner ecosystem
icon benefits data leakage prevention

Data leak protection

File protection controls to prevent sensitive data exfiltration 

FortiGate IPS Models and Specifications

FortiGate IPS is available in different form factors and models to meet the needs of your environment. All models offer full FortiGate IPS functionality and can be managed across all form factors in a single FortiManager-FortiAnalyzer instance.

Ultra high-end IPS
IPS Throughput
120 Gbps
Ports
Varied
IPS Throughput
60 Gbps
Ports
Varied
IPS Throughput
60 Gbps
Ports
Varied
IPS Throughput
18 Gbps
Ports
2x 40GE QSFP+, 2x 10GE SFP+, 2x GE RJ45
Chassis IPS
IPS Throughput
170 Gbps
Ports
4x 100GE QSFP28, 24x 25GE SFP28, 3x 10GE SFP+,2x GE RJ45
IPS Throughput
110 Gbps
Ports
4x 100GE QSFP28, 24x 25GE SFP28, 3x 10GE SFP+,2x GE RJ45
High-end IPS
IPS Throughput
32 Gbps
Ports
10x 100GE QSFP28,16x 10GE SFP+, 2x GE RJ45
IPS Throughput
30 Gbps
Ports
6x 100GE QSFP28, 16x 10GE SFP+, 2x GE RJ45
IPS Throughput
30 Gbps
Ports
4x 100GE CFP2, 4x 40GE QSFP+ 8x 10GE SFP+, 2x GE RJ45
IPS Throughput
28 Gbps
Ports
4x 40GE QSFP+, 20x 10GE SFP+/GE SFP, 8x SFP+, 2x GE RJ45
IPS Throughput
26 Gbps
Ports
48x 10GE SFP+/GE SFP, 2x GE RJ45
IPS Throughput
22 Gbps
Ports
32x 10GE SFP+/GE SFP, 2x GE RJ45
IPS Throughput
23 Gbps
Ports
16x 10GE SFP+/GE SFP, 2x GE RJ45
IPS Throughput
11.5 Gbps
Ports
10x 10GE SFP+, 2x 10GE SFP+ bypass, 34x GE RJ45
IPS Throughput
11.5 Gbps
Ports
6x 10GE SFP+, 34x GE RJ45
IPS Throughput
13 Gbps
Ports
8x 10GE SFP+/GE SFP, 16x GE SFP, 18x GE RJ45
IPS Throughput
6.8 Gbps
Ports
4x 10GE SFP+/GE SFP, 16x GE SFP, 18x GE RJ45
IPS Throughput
6 Gbps
Ports
2x 10 GE SFP+, 16x GE SFP, 18x GE RJ45
Mid-range IPS
IPS Throughput
4.2 Gbps
Ports
2x 10 GE SFP+, 8x GE SFP, 4x GE RJ45 Bypass, 22x GE RJ45
IPS Throughput
5.2 Gbps
Ports
2x 10 GE SFP+, 10x GE RJ45, 8x GE SFP
IPS Throughput
5 Gbps
Ports
18x GE RJ45, 16x GE SFP
IPS Throughput
2.2 Gbps
Ports
18x GE RJ45, 4x GE SFP
IPS Throughput
500 Mbps
Ports
20x GE RJ45, 2x Shared Port Pairs
FortiAnalyzer
Devices/VDOMs (maximum)
150
GB/Day of Logs
100
Collector Sustained Rate (logs/sec)
4500
Devices/VDOMs (maximum)
200
GB/Day of Logs
200
Collector Sustained Rate (logs/sec)
9000
Devices/VDOMs (maximum)
2000
GB/Day of Logs
600
Collector Sustained Rate (logs/sec)
27000
Devices/VDOMs (maximum)
2000
GB/Day of Logs
1000
Collector Sustained Rate (logs/sec)
45000
Devices/VDOMs (maximum)
4000
GB/Day of Logs
3000
Collector Sustained Rate (logs/sec)
60000
Devices/VDOMs (maximum)
10000
GB/Day of Logs
5000
Collector Sustained Rate (logs/sec)
90000
Devices/VDOMs (maximum)
10000
GB/Day of Logs
8300
Collector Sustained Rate (logs/sec)
150000
FortiManager
Devices/VDOMs (maximum)
30
GB/Day of Logs
2
Storage Capacity
8 TB
Devices/VDOMs (maximum)
100
GB/Day of Logs
2
Storage Capacity
12 TB
Devices/VDOMs (maximum)
300
GB/Day of Logs
2
Storage Capacity
24 TB
Devices/VDOMs (maximum)
1200
GB/Day of Logs
2
Storage Capacity
36 TB
Devices/VDOMs (maximum)
4000
GB/Day of Logs
10
Storage Capacity
48 TB
FortiGate IPS, FortiAnalyzer and FortiManager virtual machines are all supported on VMware vSphere, Citrix Xen Server, Xen, KVM, and Microsoft Hyper-V.

FortiGate IPS
IPS Throughput
1 Gbps
Ports
Up to 10
IPS Throughput
1.5 Gbps
Ports
Up to 10
IPS Throughput
3 Gbps
Ports
Up to 10
IPS Throughput
6 Gbps
Ports
Up to 10
IPS Throughput
12 Gbps
Ports
Up to 10
IPS Throughput
19 Gbps
Ports
Up to 10
FortiAnalyzer IPS
Devices/VDOMs (maximum)
10000
GB/Day of Logs
1
Storage Capacity
500 GB
Devices/VDOMs (maximum)
10000
GB/Day of Logs
+1
Storage Capacity
+500 GB
Devices/VDOMs (maximum)
10000
GB/Day of Logs
+5
Storage Capacity
+3 TB
Devices/VDOMs (maximum)
10000
GB/Day of Logs
+25
Storage Capacity
+10 TB
Devices/VDOMs (maximum)
10000
GB/Day of Logs
+100
Storage Capacity
+24 TB
Devices/VDOMs (maximum)
10000
GB/Day of Logs
+500
Storage Capacity
+48 TB
Devices/VDOMs (maximum)
10000
GB/Day of Logs
+2000
Storage Capacity
+100 TB
FortiManager IPS
Devices/VDOMs (maximum)
10
GB/Day of Logs
1
Storage Capacity
100 GB
Devices/VDOMs (maximum)
+10
GB/Day of Logs
2
Storage Capacity
200 GB
Devices/VDOMs (maximum)
+100
GB/Day of Logs
5
Storage Capacity
1 TB
Devices/VDOMs (maximum)
+1000
GB/Day of Logs
10
Storage Capacity
4 TB
Devices/VDOMs (maximum)
+ 5000
GB/Day of Logs
25
Storage Capacity
8 TB
Devices/VDOMs (maximum)
+ 10000
GB/Day of Logs
50
Storage Capacity
16 TB

FortiGate IPS, FortiAnalyzer and FortiManager virtual machines are all available on Amazon Web Services and Microsoft Azure. In addition, FortiGate IPS is also available on Oracle Cloud, IBM Cloud and Google Cloud Platform.

Amazon Web Service

Microsoft Azure

Oracle Cloud

IBM Cloud

Google Cloud Platform

FortiGuard Service for FortiGate IPS

FortiGate IPS is the primary user of the FortiGuard Intrusion Prevention service, but your detection, control and security posture are greatly improved with any combination of the following FortiGuard services, many of which are included in the FortiGuard bundles.

View FortiGuard Labs Services and Bundles.

 

FG AntiSpam

反垃圾邮件

FortiGuard Antispam(反垃圾邮件)可提供一种全面且多层次的方法对组织处理的垃圾邮件进行检测、过滤。双路径检测技术可以显著地减少边界垃圾邮件数量,给您一个无与伦比的邮件攻击控制与感染控制体验。

FG Antivirus

反病毒

FortiGuard 反病毒可阻断最新病毒、间谍软件以及其他内容层面的威胁。它采用行业领先的高级检测引擎来阻止不断变化的新威胁在您的网络中获得据点、访问网络中宝贵的内容。

FG Application Control

应用控制

可对您的用户正在运行的应用程序获得无可比拟的实时可见性,并轻松执行您可接受的使用策略,从而提供安全性并满足合规要求。通过 FortiGuard 应用控制,您可以快速创建策略来允许、拒绝或限制对应用程序或整个类别的应用程序的访问。

Product Category Thumb SS security audit

Content Disarm & Reconstruction

Content Disarm & Reconstruction (CDR) strips all active content from files in real-time, creating a flat sanitized file. All active content is treated as suspect and removed. CDR processes all incoming files, deconstructs them, and removes all elements that do not match firewall policies.

Icon cloudsandbox

FortiSandbox 云

FortiSandbox 云服务是一个高级威胁检测解决方案,能够执行动态分析来提前识别未知的恶意软件。FortiSandbox 云生成的可执行威胁情报会反馈到防火墙网络安全策略配置中,进行威胁阻断。

FG IOCs DK

Indicators of Compromise

The FortiGuard Indicator of Compromise (IOC) service packages recently observed artifacts of host intrusions or compromise, delivering them daily to retroactively identify any host intrusions and proactively protect against the latest targeted attacks.

Industrial Control systems icon

工控系统

FortiGuard Industrial Security Service(工业安全服务)会持续更新签名,以识别和监控大多数常见的 ICS/SCADA (监控和数据采集)协议,以实现精细可见化和精细控制。另外还对主要 ICS 制造商的应用和设备提供漏洞保护。

FG Intrusion Prevention

入侵防御

FortiGuard IPS 通过检测威胁并在威胁侵入到网络设备前对此阻断,以此抵御最新的网络入侵。

FG AntiBotnet

IP 信誉 & 反僵尸安全服务

FortiGuard IP 信誉服务从 Fortinet 分布式威胁传感器网络、CERT、MITRE、进行合作的竞争对手以及其他全球资源收集恶意来源 IP 数据,合力提供关于敌对来源的最新威胁情报。有来自分布式网络网关近乎实时的情报,再结合 FortiGuard Labs 的世界级研究,组织可得到更安全的保护并对攻击实施主动拦截。

FG Mobile Security

移动安全

Fortinet 的移动安全服务能有效防御以移动设备为目标的最新威胁。它采用行业领先的高级检测引擎来阻止不断变化的新威胁在您的网络中获得据点、访问网络中宝贵的信息。

Security Rating Service icon

安全评级

安全审计更新服务旨在引导客户设计、实现并持续维护适合其组织的目标 Security Fabric 安全架构安全状态。Security Fabric 安全架构从根本上是构建于最佳安全实践之上,通过运行这些审计检查,安全团队将能够识别 Security Fabric 安全架构设置中的关键漏洞和配置弱点,并实施最佳实践建议。

Product Category Thumb SS virus outbreak

Virus Outbreak Protection Service

FortiGuard Virus Outbreak Protection Service (VOS) closes the gap between antivirus updates with FortiCloud Sandbox analysis to detect and stop malware threats discovered between signature updates before they can spread throughout an organization. OS initiates a real-time look-up to our Global Threat Intelligence database.

FG Web Filtering

网页过滤

通过对恶意、被侵入或不当网站的访问阻拦来保护您的组织。

   

FortiGuard Service Bundles for FortiGate

Enterprise Protection Bundle

Protection to address today's advanced threat landscape. It delivers all FortiGuard security services available for the FortiGate including: NGFW Application Control and IPS, Web Filtering, FortiCloud Sandbox, Antivirus, Mobile Security, IP Reputation & Antibotnet, Antispam, and core FortiCare security services with a choice of 8x5 or 24x7 support.

UTM Protection Bundle

Traditional UTM security services including NGFW Application Control and IPS, Web Filtering, Antivirus, Antispam, and core FortiCare security services with a choice of 8x5 or 24x7 support.

Threat Protection Bundle

Core protection technologies including: Application Control, IPS, AV, Botnet IP/Domain and Mobile Malware Service. FortiCare security services include 24x7 support. 

You can find more information here.

FortiGate IPS Demo

product demo fortiguard ips

FortiGate IPS Demo

Try out FortiGate IPS for yourself and see all of the detection capabilities and incident monitoring possible in this world-class IPS solution.

Access the demo
product demo fortigate 1500d

FortiGate Next-Generation Firewall Demo

This full working demo lets you explore the many features of our FortiGate Next-Generation Firewall (NGFW). You’ll quickly see how FortiGate allows you to enable threat protection features such as IPS, Web-Filtering, Anti-Malware, Cloud Sand-box and SSL inspection to stop known and unknown threats. FortiGate also provides the full visibility and identifies applications, users and devices to identify issues quickly and intuitively. Be sure to check out our Security Fabric features to provide end to end topology view, security ratings based on the best practices and automation to reduce complexity. 

Access the demo

FortiGate IPS Certification

 

NSS Labs NGIPS 2018 SVM and Report

NSS Labs’ NGIPS test is the most extensive IPS test, including several tests not conducted for DCIPS, such as live drive-by-exploits (100% block rate for Fortinet), exploits against web target types, application ID and evasions (also 100% block rate for Fortinet). The FortiGate 500E and FortiGate 3000D are world-class IPS appliance, achieving “Recommended” status again with an overall Exploit block rate of 99.5% for FortiGate 500E and 99.6% for FortiGate 3000D.

NSS Labs DCIPS 2018 SVM and Report

NSS Labs’ Data Center Intrusion Prevention Systems (DCIPS) focuses on data center environments, especially vulnerabilities commonly found in servers. The Security Value Map (SVM) shows that FortiGate IPS achieved the highest cumulative blocking rate at 98.73% and the lowest TCO at $3 per protected Mbps. Fortinet builds world-class IPS appliances and another “Recommended” IPS rating from NSS Labs proves this.

NSS Labs DCSG 2017 SVM and Report

NSS Labs’ DCSG test is a comprehensive Data Center Security Gateway (DCSG) test, including several tests to measure relevant security effectiveness and Intrusion Prevention (IPS) performance using live exploits including “weaponized” exploits (97.9% and 98% block rate respectively for Fortinet FortiGate 7060E and FortiGate 3000D) and resistance to evasion techniques (100% block rate for Fortinet). The FortiGate 7060E and 3000D both achieved “Recommended” status, with a leading combination of Security Effectiveness and Value per protected Megabit Per Second (Mbps) in the NSS Labs Security Value Map (SVM).

NSS Labs Breach Prevention Systems (BPS) Test 2017

NSS Labs introduced a new group test, BPS focused on detecting and blocking exploits, advanced malware, and evasions. This helps validate the advanced threat response cycle of prevent-detect-mitigate across a number of threat vectors including web, email, and endpoint. Fortinet's Security Fabric consisting of FortiSandbox, FortiGate, FortiMail, and FortiClient integrated together, earned a Recommended award by achieving a block rate of 99.6% and offering the lowest 3-year TCO

NSS Labs DCIPS 2016 SVM

NSS Labs’ Data Center Intrusion Prevention System (DCIPS) report is the industry’s most comprehensive test to date with their Security Value Map revealing that Fortinet’s FortiGate 3000D earned the highest ratings for Security Effectiveness, blocking 99.9 percent of exploits, and TCO (Total Cost of Ownership) per protected Mbps (Megabit per second).

NSS Labs 2015 Next Generation IPS Test

In 2015, NSS Labs conducted a group test of next generation IPS solutions to assess their abilities to identify both the applications and the users on their internal networks, protect the enterprise user against threats/exploits, and catch sophisticated attacks while producing as few false positives as possible. Demonstrating 99% effectiveness and superior value, Fortinet FortiGate earned the NSS Labs Recommendation.

ICSA Labs Certified: Antivirus, Corporate Firewall, IPsec, NIPS, SSL-TLS, and Web Application Firewall

FortiGate and FortiWeb products are evaluated against ICSA criteria in 6 popular Certification programs. ICSA Labs manages and sponsors security consortia that provides a forum for intelligence sharing among the leading vendors of security products. In addition, ICSA Labs publishes surveys, security industry studies, and buyer's guides for computer security products.

FortiGate IPS Alliance Partners

FortiGate IPS provides integration with many leading IT vendors as part of the Fortinet Security Fabric.  Below is a list of current Product Alliance Partners:

AlgosSec
AlgosSec

The leading provider of business-driven security management solutions, AlgoSec helps over 1,500 enterprises align security with their business processes, to make their organizations more agile, secure and compliant.

Attivo Networks
Attivo Networks

Attivo Networks is an award-winning innovator in cyber security defense. As the leader in deception-based threat detection technology, Attivo empowers continuous threat management using dynamic deceptions for the real-time detection, analysis, and accelerated response to cyber incidents.

Centrify
Centrify

Centrify is the leader in securing enterprise identities against cyberthreats that target today’s hybrid IT environment of cloud, mobile, and on-premises.

FireMon
FireMon

FireMon solutions deliver continuous visibility into and control over network security infrastructure, policies, and risk.

Gigamon
Gigamon

Gigamon provides active visibility into physical and virtual network traffic, enabling stronger security, and superior performance.

Technical Integration Guide

IBM
IBM

IBM Security offers one of the most advanced and integrated portfolios of enterprise security products and services. The portfolio enables organizations to effectively manage risk and defend against emerging threats.

Nozomi Networks
Nozomi Networks

Nozomi Networks is a leading provider of real-time visibility, advanced monitoring capabilities, and strong security for industrial control networks supporting critical infrastructure. Nozomi has been deployed in some of the largest industrial installations, providing some of the fastest return-on–investment in the industry.

ServiceNow
ServiceNow

ServiceNow makes work better. Our applications automate, predict, digitize and optimize business processes across IT, Customer Service, Security Operations, HR and more, for a better enterprise experience.

Splunk
Splunk

Splunk Inc. is the market-leading platform that powers Operational Intelligence.

Tufin
Tufin

Tufin leads the Security Policy Orchestration market, enabling enterprises to centrally manage, visualize, and control security policies across hybrid cloud and physical network environments.

UBiqube
UBiqube

UBiqube is a vendor-agnostic provider of end-to-end network and security orchestration solutions. UBiqube’s MSActivator™ is a multi-tenant software framework enabling the design, automation, and management of services over hybrid communication infrastructures (SDN/NFV/IoT).

FortiGate IPS FAQs

Does Fortinet really build IPS technology?

Although better known for firewalls, Fortinet has built IPS products for more than 10 years, participating in NSS Labs IPS testing for the past few years and receiving “recommended” ratings with detection and blocking scores better than many of the traditional IPS vendors. Chose the IPS form factor that suits you best – either standalone IPS or IPS integrated into the firewall.

How is FortiGate IPS different from IPS offered by other firewall vendors?

IPS products that are bolted on to firewall platforms are usually an afterthought and tend to be a massive performance burden. It is not uncommon to see more than 80% performance degradation when turning IPS inspection on in many firewalls. FortiGate IPS and FortiGate firewalls were part of the inspection path from the beginning, designed with parallel path processing in all form factors and having the benefits of Security Processing Units (SPU) in hardware form. This is why FortiGate IPS was capable of 131 Gbps throughput as verified by NSS Labs on the FortiGate IPS 7060E. Value and IPS performance are not an issue for FortiGate IPS. 

How are IPS and Firewalls different?

Fundamentally, a firewalls is tasked with access control, based on a set of access rules. IPS is tasked with content inspection. While both try to keep bad traffic out of your network, they go about it in different ways. Firewalls can usually determine whether a network flow should be allowed into the network by discerning the application type and user information. This often requires only inspecting the first few packets in a flow or even just the packet headers. This is a good thing, making firewall inspection very efficient. In contrast, IPS needs to inspect the entire flow, in order to determine if the payload or intent of the flow is malicious. That can mean inspecting every packet or even inspection across multiple flows to fully examine payload. This is a lot more work and while firewall and IPS functions can absolutely reside on the same appliance, do not let your IPS capability be strangled by a platform that is only optimized to look for application type or user.

Can Firewalls and IPS be managed together?

Absolutely yes. FortiGate IPS and FortiGate firewalls (and several other Fortinet technologies) are managed by the same central management system – FortiManager and FortiAnalyzer – often sharing the same settings and configurations. In fact, this central management system extends across environments seamlessly with a single-pane-of-glass, from hardware to virtual machines to public cloud instances.