What I have is an FTP server that only allows IP specific connection to my server...
When a foreign IP attempts to login the FTP server logs the IP and then denies them. I look at my log, NeoTrace back to the ip if I dont like the location where its coming through I will go and set and advanced rule in my sygate firewall to block either a specific IP (which 1 rule only allows for 5 IPs if I remember correctly) or an IP range.
Then in theory that ip is not even allowed in to access my FTP server because it has been blocked before it enters my system...
I'd like to think of it as semi-secure... but I'd rather not be hacked to find if it really is. (lol, if you cant see it its not there... right?)
So thats what I do for one of my systems.
I am not sure if it will detect FTP attacks simply because I want my FTP server to be semi-visible in order to have my associates connect to it from the outside world. I will have to check into that if there is a feature that will assist with that.
-Demon