Snort mailing list archives
Re: Snort as Gigabit Sensor
From: Jeff <jcoppock1 () comcast net>
Date: Sat, 26 Jul 2003 19:17:51 -0700
Jason Haar, 2003-Jul-25 12:06 +1200:
Jeff wrote:Some other posts to this thread talk about getting the max performance out of a single system, up to 300-500Mbps. To get a full Gig (well 700Mbps or so anyway) of IDS traffic you'll need to load balance a server farm. Check out the Nortel Alteon Web Switches which have IDSCan I just ask a naive question? Needing to load balance is only due to the sites requiring PCI-based IDS isn't it? I mean, there are Gb IDS out there - they wouldn't need load balancers would they?
Right. Farming multiple 100-300Mbps systems and load-balancing is one option.
Pretty scary: Gb Ethernet isn't exactly cutting edge these days - being required to go over to load balancers must really change the budget requirements...
Chad and Andrew make very good points. If you really are pushing 1GB, then load-balancing is one option, another option being to build a high-speed system. Chad makes some great points about some advantages of load-balancers. Providing high-availability to you IDS farm is nice. Also, being able to filter traffic to specific IDS systems is also nice. jc -- Jeff Coppock Systems Engineer Diggin' Debian Admin and User ------------------------------------------------------- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual Studio .NET. http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort as Gigabit Sensor Banniza Robert (Jul 24)
- Re: Snort as Gigabit Sensor Erek Adams (Jul 24)
- Re: Snort as Gigabit Sensor Demetri Mouratis (Jul 24)
- Re: Snort as Gigabit Sensor twig les (Jul 24)
- Re: Snort as Gigabit Sensor Bennett Todd (Jul 24)
- Re: Snort as Gigabit Sensor Jeff (Jul 24)
- Re: Snort as Gigabit Sensor Jason Haar (Jul 24)
- Re: Snort as Gigabit Sensor Jeff (Jul 26)
- DCOM exploit snort signature jason (Jul 27)
- Re: Snort as Gigabit Sensor Jason Haar (Jul 24)
- Snort in Linux kernel mode Paul B. Poh (Aug 05)
- <Possible follow-ups>
- RE: Snort as Gigabit Sensor Banniza Robert (Jul 24)
- RE: Snort as Gigabit Sensor twig les (Jul 24)
- Re: Snort as Gigabit Sensor Irwan Hadi (Jul 27)
- Re: Snort as Gigabit Sensor Marc Quibell (Jul 24)
- RE: Snort as Gigabit Sensor Banniza Robert (Jul 24)
- RE: Snort as Gigabit Sensor Hutchinson, Andrew (Jul 25)
- RE: Snort as Gigabit Sensor Kreimendahl, Chad J (Jul 25)
- RE: Snort as Gigabit Sensor Kreimendahl, Chad J (Jul 29)