EFW Support

Support => General Support => Topic started by: arminf on Sunday 30 May 2010, 11:50:46 pm



Title: Firewall Option "allow" vs. "allow with IPS"
Post by: arminf on Sunday 30 May 2010, 11:50:46 pm
Help me understand...

Every Firewall Rule can be set with 2 Different Security Option

"ALLOW" -> means scan for Anti Virus
"ALLOW with IPS" -> scan with Anti Virus  PLUS use SNORT IPS

Does this switch work for you?

Example:
InterZone Firewall
Green to Green is set to "Allow" so no SNORT should be used.
This does not work for me. As long as i use IPS on in Service option the "allow" button does include IPS.
But when is disable IPS service the Green to Green speed is normal and about 50/60MB instead of 5/7 MB

Green to Green is my LANside. IPS should only scan cross connections. Green to Blue, Green to Red, Red to Everywhere.
Not inside the Networks (green/green, Blue/blue)

How do you configure your InterZone or SNORT to get internal speed?

Any hint?

thanks Gents!



Title: Re: Firewall Option "allow" vs. "allow with IPS"
Post by: Thilo on Wednesday 02 June 2010, 11:48:34 pm
same issue...


Title: Re: Firewall Option "allow" vs. "allow with IPS"
Post by: arminf on Thursday 03 June 2010, 02:14:08 am
Thx Thilo!

Anybody else has this issue?

You should feel it when you copy a bunch of data through your networks.

DMZ to LAN, LAN to DMZ, WLAN to LAN, LAN to WLAN, WLAN to DMZ, DMZ to WLAN

You can disable IPS and check the speed
then enable and check the speed

After check your FW option and set to allow and NOT allow with IPS.
When you copy now your result is same as in case 2.

Could somebody please test this case. this drives me mad...

Any help is highly appreciated!!!!!

THANKS GENTS!