Hi all,
Just a small question, what's better? Doing 1 rule including ALL the needed services for ingress egress destination OR doing multiple rules (one per targeted services)?
Thanks,
Regards,
M-
This thread was automatically locked due to age.
Depending on the number of rules you end up with, I use a combination. One of the benefits for me is to identify which rule is malfunctioning and verifying which rule applies to the traffic being logged. I generally lump things together in groups by function. Email - 1 rule for outbound. Web browsing - 1 rule. I create rules for traffic I don't want logged, then log everything else. You will probably not get to the point that you have so many rules that if affects performance.