As soon as the system was switched on, I noticed the sort of traffic that should not be internal to a DMZ. The ISP-controlled firewall had been misconfigured to allow almost all traffic.In the short time the test was running, the IDS logged a large number of port scans and access attempts on the main servers.