get created with action = block. Is this correct?
how everything (rules, newly downloaded rules, and ISP mode) is intended to work together.
1. Alerts 2. Alerts 3. Drops
When enabled, the system can drop suspicious packets. In order for this to work, your network card needs to support netmap. The action for a rule needs to be “drop” in order to discard the packet, this can be configured per rule or ruleset (using an input filter).