HI, I have setup IPS for some testing. The IPS sensor is configured to
use the signature default setting for the activity. It seems working
well and I get some allerts. like date=2012-04-11 time=05:18:21
device_id=FG300Bxxxx log_id=16384 subtype=sign...
Hello Ede, you are right. I should optimize the signature only to that
what is behind this access. So Server and the OS selection should help
to limit the numbers of signaures that would be checked in case of
access. Have not yet done so for my initi...
Hello Ede, many thanks. As I had up to now only status detected, I wasn'
t aware that this will changed to drop if this is blocked. BTW: do you
have any idea why it is detect but this special type isn' t seen in the
predefined signature? Thanks Jens