Monitoring
Remember to look through the logs from time to time, particularly if you put in rules that are designed to detect attacks. Furthermore, just in case someone does break in, you might want to have a trusted internal host doing your syslogging for you.
tcpd, tripwire, courtney, and all the other tools don't do any good if they are not properly used and checked. The first thing an attacker does is look for these things. Time is what your firewall is buying you. However, time works for the attacker and against you. The best time to catch an attack is before the penetration occurs, when your network is being probed. To enter, an attacker must find your weaknesses. This way, you will have warning. It might not be much, though.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access