Hi,
I upgraded my home firewall from IPCop (and m0n0wall) to Astaro 6.2. With IPCop, i received regular SNORT alerts, often things like SQL expoits originating from China (3-4 per day, for example).
My Astaro 6.2 has been running for 3 days, and I have not seen any external attack alerts. I have received numerous internal alerts (MSN, Skype, AOL, etc), so I know SNORT is running OK. I can't believe it's just luck that I haven't had any external issues. My IDS interface box is "empty", so all interfaces/networks should be monitored.
So...my only theory is that SNORT as deployed here only reports issues with open ports. Is that the case? My rules only permit forms of outbound traffic, but no incoming.
In other words, will I only see external threats if they are attempting to exploit open ports?
Thanks in advance! I'm thrilled qith the quality and features of this product!
Rich
This thread was automatically locked due to age.