Security Basics mailing list archives

Re: Network IDS


From: "Gabriel Orozco" <gabriel_orozco () mx sumida com>
Date: Fri, 15 Aug 2003 18:01:00 -0500

Maybe your employee does not want to know about *nix solutions, but alas,
the best products are flying around there...

go to the snort web page, and look for their NIDS BOX, which it's a box, and
have a very nice web management app, and of couse, should sit between your
network and the servers network.

this way you will not install *nix and then snort, but buy a box with one of
the better IDS out there

Regards

----- Original Message -----
From: "Duston Sickler" <dustons () charter net>
To: <security-basics () securityfocus com>
Sent: Friday, August 15, 2003 12:30 PM
Subject: Network IDS


Hello,

I would like to thank in advance everyone who is out of the office.  I
really do like to hear about it.

The Network Administrator for the company I work for has charged me to
locate a Network Intrusion Detection System.  We do have a monitored
firewall between us and the outside world.  We need something to protect
our
servers from anyone coming from the inside.  We have about 20 Windows 2000
Servers, 5 NT 4 Servers, and 250 Windows 2000/Thin Net workstations.

We live in a 100% Windows world and the powers that be will not be
receptive
to any *nix solutions.  We are more the willing to pay for a top of the
line
product as long is it is in fact top of the line.

Currently I have been looking at the Symantec Gateway Device.  We like the
idea of a stand alone piece of hardware.  The only problem is we already
have a gateway server washing our email of viruses and 99% of Spam.

Does anyone have any comments on the Symantec Gateway device?  We have had
excellent experiences with there Gateway software and NAV Corp.  Does
anyone
have a different or better device that they could point me towards?

I would like to thank everyone who replies to this post.  I have learned a
great deal being on this list the last year and will continue to
appreciate
all the expertise that is freely given here.

Duston Sickler
CompTIA A+ Certified
"Cedo nulli."


--------------------------------------------------------------------------
-
--------------------------------------------------------------------------
--




---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.507 / Virus Database: 304 - Release Date: 04/08/2003


---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: