Alert Filter or not for : TCP:ACK PortScan and more
Hi I want to eliminate false postivs. I see on the outside Interface our Firewall very often the attack called: TCP: Ack Portscan . That normal .
What you guys doing with this attack ? What you filter out ?:confused: If I create a Alert filter e.g. everthing from outside to FW interface I will lose all Information is thats right or to I have the attack anywhere else on the Intrushield ?