nanog mailing list archives
Re: Checkpoint IPS
From: "Roland Dobbins" <rdobbins () arbor net>
Date: Thu, 05 Feb 2015 20:34:36 +0700
On 5 Feb 2015, at 19:57, Terry Baranski wrote:
I hate to be the bearer of bad news, but everything we do is "artificial". There are no routers in nature, no IP packets, no fiber optics. There is no such thing as "natural engineering" -- engineering is "artificial" by definition.
This isn't even worthy of comment, so I won't.
But there's no overstating the usefulness of a properly-tuned IPS for attack prevention
I've never heard a plausible anecdote, much less seen meaningful statistics, of these devices actually 'preventing' anything.
I have, however, run into many, many situations in which these devices demonstrably degraded the security posture of network operators, particularly when placed in front of servers or broadband access networks. For example, they're laughably easy to DDoS due to state exhaustion - which is what is the main point of the presentation you reference.
And the fact that well-known evasion techniques still work against these devices today, coupled with the undeniable proliferation of compromised hosts residing within networks supposedly 'protected' by these devices, militates against your proposition.
----------------------------------- Roland Dobbins <rdobbins () arbor net>
Current thread:
- Re: Checkpoint IPS, (continued)
- Re: Checkpoint IPS Michael O Holstein (Feb 05)
- Re: Checkpoint IPS Roland Dobbins (Feb 05)
- RE: Re: Checkpoint IPS Darden, Patrick (Feb 05)
- Re: Checkpoint IPS Skeeve Stevens (Feb 05)
- RE: Checkpoint IPS Darden, Patrick (Feb 05)
- RE: Checkpoint IPS Terry Baranski (Feb 05)
- Re: Checkpoint IPS Michael Hallgren (Feb 05)
- Re: Checkpoint IPS jim deleskie (Feb 05)
- Re: Checkpoint IPS Michael Hallgren (Feb 05)
- Re: Checkpoint IPS Nick Hilliard (Feb 05)
- Re: Checkpoint IPS Roland Dobbins (Feb 05)
- Re: Checkpoint IPS Terry Baranski (Feb 05)
- Re: Checkpoint IPS Valdis . Kletnieks (Feb 05)
- Re: Checkpoint IPS Terry Baranski (Feb 05)
- Re: Checkpoint IPS Roland Dobbins (Feb 05)
- RE: Checkpoint IPS Terry Baranski (Feb 05)
- Re: Checkpoint IPS Roland Dobbins (Feb 05)
- Re: Checkpoint IPS Patrick Tracanelli (Feb 05)
- Re: Checkpoint IPS Ray Soucy (Feb 06)
- Re: Checkpoint IPS Roland Dobbins (Feb 06)
- Re: Checkpoint IPS Patrick Tracanelli (Feb 06)