This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is IPS even working?

Hi

I'm a bit concerned....
I have two firewall rules, which allow internet access:
- LAN to WAN
- DMZ to WAN
And I assigned those two IPS-rules to the firewall rules:
- LAN TO WAN
- DMZ TO WAN

As I have read here in the forum, the rules also affect the traffic in the other way, so in this case:
- WAN to LAN
- WAN to DMZ

Now I created a test machine in my DMZ and made a DNAT to this for port 1111 to port 80 on the machine. And for RDP. (For those business rules I also attached the IPS rules)
Now I tested port scanning, multiple Metasploit exploits for RDP and apache.
But the XG isn't showing any attacks, neither in the reports nor in the dashboard.

What am I doing wrong??

Thanks for your help in advance and greetings
Luca



This thread was automatically locked due to age.