FortiGate Version 3.0 MR4 Administration Guide
282 01-30004-0203-20070102
Adding a protection profile to a policy Firewall Protection Profile
For more information about logging, see “Log&Report” on page 407.
VoIP options
The FortiGate unit supports rate limiting for SIP (including SIMPLE) and SCCP
protocols.
Figure 174:Protection profile VoIP options
The following options are available for VoIP through the protection profile:
Adding a protection profile to a policy
Enable protection profiles for firewall policies with action set to allow or IPSec and
with service set to ANY, HTTP, FTP, IMAP, POP3, SMTP, or a service group that
includes these services.
If virtual domains are enabled on the FortiGate unit, protection profiles must be
added to policies in each virtual domain. To access the policy, select a virtual
domain from the main menu.
1 Go to Firewall > Policy.
2 Select a policy list to which to add a protection profile.
For example, to enable network protection for files downloaded from the web by
internal network users, select an internal to external policy list.
3 Select Create New to add a policy, or select Edit for the policy to modify.
Web Filtering Content Block Enable logging of content blocking.
URL Block Enable logging of blocked and exempted URLs.
ActiveX Filter Enable logging of blocked Active X.
Cookie Filter Enable logging of blocked cookies.
Java Applet Filter Enable logging of blocked Java Applets.
FortiGuard Web
Filtering
Log rating errors (HTTP
only)
Enable logging of rating errors.
Spam Filtering Log Spam Enable logging of spam detected.
IPS Log Intrusions Enable logging of signature and anomaly
intrusions.
IM and P2P Log IM Activity Enable logging of IM activity.
Log P2P Activity Enable logging of P2P activity.
VoIP Log VoIP Activity Enable logging of VoIP activity.
Limit RIGISTER Request Set a rate limit to SIP RIGISTER requests (per second).
Limit INVITE Request Set a rate limit to SIP INVITE requests (per seconds).
Limit Call Setup Set a rate limit to SCCP call setup (calls per minute)
between call clients and the call manager.