Enable ASL Network Firewall IPS

Customer support forums for Atomic Protector (formerly Atomic Secured Linux). There is no such thing as a bad question here as long as it pertains to using Atomic Protector. Newbies feel free to get help getting started or asking questions that may be obvious. Regular users are asked to be gentle. :-)
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

Enable ASL Network Firewall IPS

Unread post by faris »

What does "Enable ASL Network Firewall IPS" do?
The default is apparently "yes".

I searched the Wiki and the forum, but couldn't find anything as there were too many matches that were unrelated. I have a feeling I might even have asked this before (embarrassed).
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Enable ASL Network Firewall IPS

Unread post by mikeshinn »

What does "Enable ASL Network Firewall IPS" do?
The default is apparently "yes".
It protects against attacks that either need to done down at layer 3, or in cases where application firewalls are either too late or simply are impractical for the protocol. As we add new capabilities we'll update the wiki on this feature to tell you what we've added.
I searched the Wiki and the forum, but couldn't find anything as there were too many matches that were unrelated. I have a feeling I might even have asked this before (embarrassed).
My bad, I forgot to add that to the wiki. Added now:

https://www.atomicorp.com/wiki/index.ph ... all#FW_IPS

Also contains a link to the page that contains a broader explanation for the system:

https://www.atomicorp.com/wiki/index.ph ... ion_System
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

Re: Enable ASL Network Firewall IPS

Unread post by faris »

Thanks.

btw, the WiKi says default = no which is different to what it says in the GUI.

Related: Is there a way to test for IPS support? We use Virtuozzo, and not all netfilter modules are supported.
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Enable ASL Network Firewall IPS

Unread post by mikeshinn »

The kernel has to support the u32 and strings modules. So if virtuzzo doesnt have those loaded then the IPS wont enable.
Post Reply