Our company is new to the Astaro security gateway. I have been placed in charge of managing much of the security settings myself, but I am still having a hard time figuring out what settings to use for intrusion protection.
I apoligize, these are very basic questions, but I can't seem to find real answers so here goes.
*************************
On the Intrusion Protection Rules page I see three un-names colums (why not names the columns. Is that really too much to ask as a feature of a premiere network product? Here they are:
Column 1: green - red light
What do they mean? Does the first box mean notification and the second mean permission? Please help?!?!
Column 2: Permissions (?)
Column 3: Details folder
Our office uses Skype. I get hundreds of notifications on P2P policy violations. I want to allow the Skype traffic but not trigger any notifications. What does the first colum need to be set to and what does the 2nd column need to be?
We also want to block all chat/IM software and not be notified. What should the setting be for this?
As an inexperienced network manager I am very frustrated with the lack of labels on the GUI. I would expect the colums to have headings and settings to be identitfied if I mouse-over to tell me what the setting means.
Help anyone?
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
Thanks for the notes on the version update. For some reason, the consulting company we use does not recommend teh upgrade. I am not sure why.
I am getting notified of a potential sercurity risk about 10 times a day.
Subject: [WARN-854] Anomaly Intrusion Protection Alert
Message........: Source used odd dest port: local source, syn: 0.9272
Time...........: 2007:04:27-07:09:07
Packet dropped.: no
IP protocol....: 6 (TCP)
We have about 20 employees on the web and I think this is a notification about an internal IP hitting dead pages on the outside web. Does that sound correct? I tried to disable to notification, but can't really locate the place to do it.
Can anyone help?
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.