Hello,
is it possible to enable IPS, but not blocking any traffic?
I just want to log possible IPS attacks.
Greetings,
Michael
This thread was automatically locked due to age.
Hello,
is it possible to enable IPS, but not blocking any traffic?
I just want to log possible IPS attacks.
Greetings,
Michael
I think, "Allow Packet" will simply log but not Drop the Session.
I thought the same, but...
I can see some Network Attacks (PROTOCOL-DNS single byte encoded name response) in the control center of the firewall, but i can't see them in the log viewer when i filter to "Log comp is IPS"
HI,
I have a similar issue, i see attacks in the IPS tab, but nothing in the logviewer telling me who was being attacked. There is additional information in the Reports tab, but not sufficient to identify who was being attacked.
Ian
Hi Micheal,
if you click on that widget it should open a series of graphs showing you the device/s affected. Also this traffic does appear in logviewer, try looking at the various selections.
What doesn't show in the log viewer is the attacks shown in the IPS tab.
Ian
Hi Micheal,
if you click on that widget it should open a series of graphs showing you the device/s affected. Also this traffic does appear in logviewer, try looking at the various selections.
What doesn't show in the log viewer is the attacks shown in the IPS tab.
Ian