Meridian Electric Cooperative is enabling IPS on a substation link for the first time and wants to see which signatures would actually fire against real traffic before any of them are allowed to interrupt substation communications. Which rollout approach fits how FortiGate IPS is designed to be tuned in?
Select an answer to reveal the explanation.
Short Explanation
Before you flip an alarm system to "call the police," you run it in test mode and just watch which sensors trip. Monitor action does exactly that for IPS: it tells you what would have fired, without a single substation session getting cut off while you learn.
Full Explanation
Setting a sensor's signatures to the Monitor action lets FortiGate log every match against real substation traffic while still forwarding the session, so administrators can review which signatures actually fire in that environment and switch only the validated ones to Block once confident the matches represent real threats rather than normal operational traffic. Leaving every signature at its recommended default and going straight to full production skips that observation step entirely, so any signature that happens to match legitimate substation traffic starts dropping sessions on day one with no prior visibility into what would be affected. Disabling inspection during the trial defeats the purpose of the rollout, since no data about which signatures would match is ever collected, leaving the eventual switch to enforcement just as untested as turning the sensor straight to Block. Relying on interface traffic counters gives volume information only; counters have no concept of a signature match, so they cannot tell an administrator which specific signatures would have triggered or against which flows. A caveat: Monitor still logs and can generate alerts, so make sure log storage and alerting thresholds can handle a monitoring-period signature that fires frequently. Verify readiness for enforcement by reviewing the IPS log for the trial period and confirming each candidate signature's matches are traffic the team recognizes and accepts as safe to block.