This is the mail alert I receive from CPMAD when my system is port-scanned:
25May2001 10:29:58 ACCEPT localhost  >daemon alert product MAD proto ip src 
guardian.co.tt dst My_Firewall additionals:  attack=blocked_connection_port_scanning

I have a rule that drops all connection attempts to  firewall:
ANY>My_Firewall>ANY>DROP

Can anyone tell me why in MAD mail I see ACCEPT while in reality connection must be 
dropped?

-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to