Snort mailing list archives

Re: Re: [Snort-devel] IDS vs IPS


From: Jeff Nathan <jeff () snort org>
Date: Sat, 30 Aug 2003 17:02:19 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Mark,

not entirely true.  Dan Hartmeier's packet filter is rather impressive.

- -Jeff

On Wednesday, August 27, 2003, at 09:21 PM, Mark Teicher wrote:

I disagree, New IPS is not the natural evolution of the existing firewall, it is natural evolution of marketing hype. !!! Good firewall code just doesn't exist anymore, except for the Ultimate Firewall toolkit....!!!

At 09:16 PM 8/27/2003, Jason wrote:

Thanks, I think the matrix shows fairly well that the _new IPS_ is a natural evolution of the existing firewall.

This is important to point out because there are existing investments in firewalls and these firewalls are rapidly closing the gap where needed. I know that CP has been moving in this direction for a while. It has also been my experience that they have been moving at an appropriate pace and the capabilities have been there when I've needed them.

One final statement. You do not need the firewall to log content if you have an IDS that you can trust will not have a direct impact on the business should it be too critical of the data.

You can also have confidence in your firewall because your IDS verifies what you told the firewall to do and covers your arse when you let something by because of business requirements or a human error.



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


- --
http://cerberus.sourcefire.com/~jeff       (gpg key available)
"Problems cannot be solved at the same level of awareness that
created them."   - Albert Einstein
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (Darwin)

iD8DBQE/UTsPEqr8+Gkj0/0RAhjFAJ480+YxvEK7+MSnsLHAFOfILGumwgCfXYrm
ro5KWvJrTOOg/xSZyGvDHD0=
=9Etz
-----END PGP SIGNATURE-----



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: