When I setup this whitebox with 7.305, it is showing External (Network) in the Local Networks box under the Network Security->Intrusion Protection->Global Tab. Is that correct? Shouldn't it be sniffing traffic on the external interface? Or does it sniff the passed traffic after it passes all other filters? If so, this would seem to be counter intuitive if someone is trying to penetrate your box and it drops all the suspicious packets you may not know in time to prevent a successful attack.
I am a noob at this and I know its probably painfully obvious. I was just confused.
Thanks,
isildur
This thread was automatically locked due to age.