11.1. NIPS Settings

NIPS (Network Intrusion Prevention System) parameters can be set in the Intrusions section (see figure 10.1. The Intrusions section).

Use the Enable NIPS module option to enable/disable the intrusion prevention system.

Intrusion Detection — NIPS Settings

Figure 11.1. Intrusion Detection — NIPS Settings

Kerio Personal Firewall distinguishes between three intrusion types:

Firewall behavior can be set for individual types using the following options:

Use the Details button to open a window providing outline of intrusions of the particular type.

Intrusion Detection — Details of intrusions

Figure 11.2. Intrusion Detection — Details of intrusions

The dialog provides name or description of the attack (the Attack column) and class of the intrusion (the Class column). Kerio Personal Firewall uses the Snort type of IDS — for detailed information on individual attacks and attack types go to the http:/www.snort.org/ website.

So called Port Scanning is a special attack type (detection of open ports on a particular computer). Such attacks cannot be blocked if any ports of the user are open (closed ports are blocked automatically), they can only be detected. Use the Log to intrusions log option to enable/disable logging information on Port Scanning to the Intrusions log.