Firewall Wizards mailing list archives

Re: RE: IDS (was: FW appliance comparison)


From: "Marcus J. Ranum" <mjr () ranum com>
Date: Tue, 24 Jan 2006 22:26:31 -0500

Cat Okita wrote:
That's the main reason why I don't like IDSs. A default deny
policy combined with "log everything" achieves just the same.

*blink* You don't bog down your firewall to the point of being
unuseable doing that?!?

If your firewall bogs down because of a little bit of logging it is
a POS and should be used as a flower planter, not a security
device.

mjr.

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: