Forums

Resolved
0 votes
Intrusion prevention isnt showing any blocked threats or ip's.
I know ive been hit with SSH attacks when i have it open and running for remote stuff. Ive seen the same idiot trying to get in over and over on one day but nothing was showing up.
Under COS 5.2 I would have 10 blocked in there at a minimum all the time.
What gives? Glitch?
Friday, March 08 2013, 07:27 PM
Share this post:
Responses (2)
  • Accepted Answer

    Thursday, March 14 2013, 07:45 PM - #Permalink
    Resolved
    0 votes
    Thanks Nick
    The reply is currently minimized Show
  • Accepted Answer

    Friday, March 08 2013, 09:20 PM - #Permalink
    Resolved
    0 votes
    There are very few block rules in the default installation. Many of the 5.2 rules were very old/obsolete. If you want better rules go to Emerging Threats. Go for the No GPL rules so you won't get any clash with the supplied rule set. Alternatively you can take out a ClearCare subscription.

    As a separate line of defence, quite a few people have posted about Fail2ban which sounds quite good.
    The reply is currently minimized Show
Your Reply