Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

TZ180 - enable IPS?? How?

Status
Not open for further replies.

Prizmm

Instructor
Mar 8, 2004
124
0
0
US
Im interested in enabling IPS on my sonicwall, but Im not totally sure of the correct way. Do I want to enable it on the WAN or the LAN or both? Also, do I want to "Prevent All" or "Detect All?" Thanks
 
You should enable it on both WAN and LAN interface zones.

As for Prevent All and Detect All - I would suggest enabling Detect All for all three priority attacks and Prevent All on High and Medium attacks. I find that I get some cross VPN Active Directory replication issues when I have low priority attacks prevented.

Of course the best method is to Detect and Prevent all attack classes and then, using the log viewer, selectively disable prevention on the low priority, legitimate traffic you see.

hope this helps,

Oscar.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top