Greetings,
Is there any way to turn off IPS for a specific service or machine?
Situation:
Client has ASG220 running IPS. They have a FTP/SFTP (SSH) server running on the LAN that is NAT'd with an additional IP address on the WAN interface. This server cannot be moved from the LAN, due to time-sensitive proprietary software which relies on file transfers being stored on a network share on the LAN (in other words, moving the server to a DMZ then synching the data to the LAN won't work).
This server is responsible for more than 50% of the traffic going through the Astaro. When IPS is running, remote FTP users complain of slow or dropped transfers. With IPS turned off the performance improves significantly.
I'm basically looking for a way to exclude IPS scanning from the FTP/SSH traffic running to this computer only. Is this possible? If not, does anyone have some suggestions for a work-around?
Thanks
This thread was automatically locked due to age.