Im interested in enabling IPS on my sonicwall, but Im not totally sure of the correct way. Do I want to enable it on the WAN or the LAN or both? Also, do I want to "Prevent All" or "Detect All?" Thanks
You should enable it on both WAN and LAN interface zones.
As for Prevent All and Detect All - I would suggest enabling Detect All for all three priority attacks and Prevent All on High and Medium attacks. I find that I get some cross VPN Active Directory replication issues when I have low priority attacks prevented.
Of course the best method is to Detect and Prevent all attack classes and then, using the log viewer, selectively disable prevention on the low priority, legitimate traffic you see.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.