ASL uses iptables which is a good spi firewall..so wht is hte purpose of hte additional ips system? is it security by redundancy or something..also what software makes up hte ips? Also is hte ids snort or snort based?
Further to this william, basically opening port 80 means that all sorts of programs can use it, not just webrowsers. Admins often pull their hair out looking to block MSN or AOL, which you now can selectively filter using Astaro IDS/IPS without going crazy. This is great stuff...
This is quite an advance. I've been running a snort_inline IPS in front of my ASL in bridge mode for a while now. It's alerted on some stuff and blocked others. Some were known attacks with a low false-positive rate and others were policy based stuff. It'll be nice to have it all in one now.