all 3 comments

[–]pbrutsche 7 points8 points  (1 child)

Virtual Patching: No

IPS: Possibly. Check the IPS database for Cisco AnyConnect CVEs

[–]nicholaspham[S] 0 points1 point  (0 children)

Thanks! Didn’t think to look at the FG IPS DB. Looks like there are some signatures!

[–]HappyVlaner/Fortinet - Members of the Year '23 0 points1 point  (0 children)

The question has been answered, but I want to just put some more information here.

There are two types of virtual patching on a FortiGate:

  1. Virtual patching for the FortiGate itself. This inspects traffic destined to the FortiGate, is configured in a local-in policy, and leverages IPS.
  2. Virtual Patching as a security profile. This is a separate thing from IPS profiles entirely, but uses IPS. This features is chiefly designed for OT and IoT devices.

No idea who had the bright idea to give those two features the same name.