How can I undestand IDS work or not
Hello.
I configure FG1500 as a IDS.
Port36 mode is one-arm (sniffer)
FG create policy (ourself)
config firewall sniffer edit 4 set interface "port36" set ips-sensor-status enable set ips-sensor "sniffer-profile" next end
FG# get id : 4 status : enable logtraffic : utm ipv6 : disable non-ip : disable interface : port36 host : port : protocol : vlan : application-list-status: disable ips-sensor-status : enable ips-sensor : sniffer-profile dsri : disable ips-dos-status : disable scan-botnet-connections: disable max-packet-count : 4000
does sniffer work or not, when number of packet become more 4000?
do i should configure max-packet-count to 1 000 000?
