this has gotten worse since the ids rules were unified. In fact, now it is difficult to even understand on which protocol IDS was generated
Even when I go to look at the administrative log, I find lines like this
10:08:57.388 DenialOfService [DenialOfService xx.xx.xx.xx] Added IP to IDS block list. Duration: 1800 seconds, Description: Default DoS rule
but looking back at the IP xx.xx.xx.xx I can't find the reason for the block
it even sometimes appears in the administrative log
[2023.11.17] 11:17:35.751 DenialOfService [DenialOfService xx.yy.zz.ww] Added IP to IDS block list. Duration: 1799.9843804 seconds, Description: Default DoS rule
and it is the first line with ip xx.yy.zz.ww in the log
I expected that in the previous lines there were lines with auth failed for example.
Certainly the description should be detailed
for example
Description: Default DoS rule - SMTP protocol excess connections on port 25
Sabatino Traini
Chief Information Officer
Genial s.r.l.
Martinsicuro - Italy