Hello everyone,
We're considering moving from Astaro V5 to V7 and I'm doing to preliminary study on the new version.
My biggest "culture shock" was the IPS: gone are my nice snort rules. Instead, I see a dozen extremely broad categories with ver little details and close to zero control.
My questions are, actually, very simple:
- How can I define custom rules ?
- How can I control individual rules behavior ?
- Is snort still used for the IPS part ?
- Has the logging been improved ? Can we now get (somehow) a full packet dump for specific rules ?
Thanks,
Stephane
This thread was automatically locked due to age.