I'm fairly new to the IPS/IDS thing, ...
Q1: is it better to switch all the rules from their default of "alert" ( = IPS) to "drop" ( = IDS, right?)? I only have a few categories which are getting any hits at all ("bad traffic", "icmp", "icmp_info", "misc", "scan", "tftp", "web-misc", and "web-php") ... the rest of the Rule Groups have zero for their hit count.
Q2: does "alert" send an email? or show up in a report that i have to go check? (if so, where is that?) or does it simply show up as a "hit" next to the Rule?
Q3: does "alert" allow the connection and just tell me about it? ... is it safer to have it "drop"?
thank you for your patience
This thread was automatically locked due to age.