 andremta
join:2009-09-24 portugal | Port Scan Detection
Hello,
Is it possible somehow with USG 300 (No IDS subscription) to detect PORT SCANS to my Network? |
|
 severach
join:2002-09-12 Jackson, MI
1 edit | I would change the firewall mode to drop by default. The default rule is the last one in the list and starts as "allow." Before you switch you will need to create a rule that allows LAN to Zywall or you will lose web access and will need to use the serial port CLI to restore it.
Enable logging on the default drop rule so you can create all the allow rules to allow the traffic you are expecting. Once those rules are working then the drop rule log will show all of your port scans. |
|