I think the new 'Attack Patterns' IPS rules on V7 is poorly designed compared to V6 where we can drill down to particular rule. A write-up in Network World agrees with my opinion as well. Here is a quote:
"We noted design issues related to adding UTM features to traffic flows elsewhere, but IPS management is a particularly weak spot from an enterprise viewpoint. With the IPS, Astaro has broken up Snort’s huge rule base into digestible chunks, but there is no way to drill down and get to individual rules, as would be needed in an enterprise network."
http://www.networkworld.com/reviews/2007/111207-utm-firewall-test-astaro.html?page=2
I understand that Astaro is trying to make IPS "EASY". The fact is that security should not be easy. What's easy for administrator is probably going to be easy for hackers. The end users should be able to control what they want, not depend on the system to make judgments.
This and this alone just seems to bring an awesome system a notch down.
This thread was automatically locked due to age.