[Snort-users] Snort as Gigabit Sensor

Jason Haar Jason.Haar at ...294...
Thu Jul 24 17:08:11 EDT 2003

Jeff wrote:

>Some other posts to this thread talk about getting the max performance
>out of a single system, up to 300-500Mbps.  To get a full Gig (well
>700Mbps or so anyway) of IDS traffic you'll need to load balance a
>server farm.  Check out the Nortel Alteon Web Switches which have IDS

Can I just ask a naive question? Needing to load balance is only due to 
the sites requiring PCI-based IDS isn't it? I mean, there are Gb IDS out 
there - they wouldn't need load balancers would they?

Pretty scary: Gb Ethernet isn't exactly cutting edge these days - being 
required to go over to load balancers must really change the budget 

[so sayeth the lucky 100M-max Snort user ;-)]


Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1

More information about the Snort-users mailing list