I am puzzled by the exceptions to Astaros IPS. I have a Astaro box with one external interface and two internal interfaces/networks.
Both these networks are protected by IPS and I would like them to stay that way. However I am constantly pushing large files between the two internal networks and the CPU on the firewall is snorting away at max capacity, seriously crippling network speed. It is my intention to turn of snort on packages traveling through the firewall origination from one of the two networks and with the other network as destination. Is this doable?
If I add two exceptions to the IPS, one making exception from IPS when traffic is coming from lan1 and with lan2 being the destination, and then another exeception only this time reversing the source and destination networks. Will this do what I want or will it simply turn of IPS completely and expose my internal networks to instrusions originating from my external interface?
Yes, I suppose this is a silly question, but the documentation isn´t really any good.
Regards Christoffer
This thread was automatically locked due to age.