Since today morning i have a problem with IPS.
My IPS is normaly activated, since tomorrow no connections are possible with activated IPS.
Here is the log after a IPS restart.
Regards
Robert
id="371Z" severity="info" sys="system" sub="up2date" name="Successfully installed Up2Date package" status="success" action="install" package_version="7.171" package="ips"
a lot of pain ... Then a modem died.
What this post is really about is when is 7.910 going to be available?
Unknown keyword ' detection_filter' in rule!
Sorry, I've seen it now! [:)]
But I can't still find a fallback mechanism to recover from bad/incompatible rules file download, even in current beta. Or am I wrong?
As an experienced VAR with many ASG hardware appliances deployed by our clients, we strongly suggest that an automated download of bad SNORT rules, AV signatures, or even a deeply tested up2date system patch, can't silently kill a core service! Most other systems (firewalls, OSes, even BIOSes) always keep a backup of previous file versions just in case anything goes wrong...
Bad IPS rules/AV signatures/etc downloads automated fallback
Sorry, I've seen it now! [:)]
But I can't still find a fallback mechanism to recover from bad/incompatible rules file download, even in current beta. Or am I wrong?
As an experienced VAR with many ASG hardware appliances deployed by our clients, we strongly suggest that an automated download of bad SNORT rules, AV signatures, or even a deeply tested up2date system patch, can't silently kill a core service! Most other systems (firewalls, OSes, even BIOSes) always keep a backup of previous file versions just in case anything goes wrong...
Bad IPS rules/AV signatures/etc downloads automated fallback