I enabled Intrusion Prevention System on all interfaces and it shows alerts from attacks, but I noticed that IPFire is not blocking them as aspected. I disabled "Monitor traffic only
What can I do to block detected attacks? I’m sure IPFire is not blocking the attacks because I run a sniffer in the target machine.
It might be worth going to the Emerging Threats site and look up what the telnet rules are expected to do. Should they block or only alert. What types of traffic will trigger them to block.