A method of monitoring and protecting a network against attacks from a
public network, particularly from the Internet, where the network
includes a firewall and an attack detection system on the protected side
of the firewall, which inspects data packets passing the firewall and
installs protective policies at the firewall in case of detecting data
packets representing an attack. Regarding high flexibility and quick
adaptability to changing attack situations, the method is characterized
in that the firewall is configured by the attack detection system in such
a way that the attack detection system or a system co-operating with the
attack detection system is provided information about data packets
representing an attack.