View Single Post
  #2 (permalink)  
Old 2006-01-08
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: SmartDefense Versus Any IPS/IDS

The shun feature of the Cisco IDS is not wery valuable thing. I have not heard that someone use it in productive environment. Only during CCIE Sec Lab preparation :) My opinion you can just forget about SHUN feature. The current hipe feature of Cisco IPS 5.1 is Rate Limiting. (This is answer for qestion #1)
This time all the vendors go from IDS to IPS. According to garner IDS are obsolete ( Are firewalls needed? ). So all the vendors adding in-line mode to the IDS sensors and rename them to the IPS. IDS is converting to the deep packet inspection firewalls. Firewalls are moving to the IDS/IPS field. CheckPoint have fast SmartDefence box - Interspect. This one to place inside you perimer, somewhrer in betwen of users and servers. (This is an answer for qestion #2 and #3)
Checkpoint accrued SourceFire IPS vendor few month ago. Lets wayt and see what will be next.
The real pain with Cisco IPS is a management. Cisco have at least 4 different softwares at the moment: IDM (IPS Device Manager) VMS 2.x (VPN/Security Management Solution) (Which is migrating to CSM3.0 currently(Cisco Security Manager)) and MARS and Cisco Incident Control System (ICS). Each have pros and cons.
Reply With Quote