This is the mail alert I receive from CPMAD when my system is port-scanned: 25May2001 10:29:58 ACCEPT localhost >daemon alert product MAD proto ip src guardian.co.tt dst My_Firewall additionals: attack=blocked_connection_port_scanning I have a rule that drops all connection attempts to firewall: ANY>My_Firewall>ANY>DROP Can anyone tell me why in MAD mail I see ACCEPT while in reality connection must be dropped? - [To unsubscribe, send mail to [EMAIL PROTECTED] with "unsubscribe firewalls" in the body of the message.]
