Quantcast
Channel: Forcepoint Community
Viewing all articles
Browse latest Browse all 2011

Log ALL traffic, not just successful connections

$
0
0

We use a variety of protection systems including IPS on the perimeter firewalls. What we've noticed is that when the firewall blocks an outbound request from the proxy due to geo protection or whatever, we cannot track it back to the user. There's nothing in the Investigative Report, absolutely nothing.

It's as if the system will not log traffic unless a TCP connection is established, which the firewall prevents. This lack of logging makes it about impossible to know who generated the IPS traffic and back-track why they did it.


Viewing all articles
Browse latest Browse all 2011

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>