Hi!
Yesterday I upgraded our ASL to version 5.011 and set the IPS to working.
We where using the Portscan Detection feature on 4.022 and it worked pretty fine. I could define networks not to be alerted as portscan origin and an action, that ASL will do (blackhole/drop).
In 5.011 this is only to be enabled or disabled...
We tested it by scanning our external IP but the traffic isn't blackholed as before!! How can I enable this again!??
I don't even get an email, as described in the help!
I really need some hints here!
Thank you!
TH
This thread was automatically locked due to age.