I am not sure if this a v7.003 isue or a NIC issue.
The problem started after I did a re-build from the v7.002 ISO and the up2date release of v7.003.
I added another NIC to put the VOiP phone on, but the way things turned out the NIC requires a special cable or a switch to do the crossover.
The new NIC (intel pro 1000) became the external interface.
Since then I have been getting a large number of packets dropped for port 80, usually ackfin type. Ifirst thought that there was a bug in the proxy, but after investigation it is caused by IPS rules 60001 and 60003. I have disabled both of those rules, yet packets are still dropped by those rules.
The original external interface was on the onboard NIC.
2 questions
1/. Is the intel pro 1000 fussier when it comes to packet format
2/. why does the IPS still block packets after the rule is disabled.
The dropped packets are not seen as intrusion attempts eg they don't appear in the IPS report only the PF log.
I will end up re-configuring the ASG so that the external interface is on the inbuilt NIC.
I do have the external and internal interfaces in the IPS as well.
Ian M[:S] [:S] [:S]
This thread was automatically locked due to age.