[Snort-users] Snort with IPSec

Josh Berry josh.berry at ...10221...
Wed Nov 5 14:02:52 EST 2003


This is not something I have control over, nor am I privy to the reason. 
This decision is being made at the director level above my group and we
are being asked how we could implement it and what the repercussions could
be.

> On Tue, 2003-11-04 at 13:02, Josh Berry wrote:
>> I understand the overhead and difficulty.  I just want to know if it is
>> technically feasible.  The reason I am asking is that one of the
>> directors
>> where I work is considering implementing site wide IPSec encryption for
>> every connection on the internal network.  This will make internal
>> attacks
>> impossible to see, therefore I cannot just sit the IDS behind the VPN
>> because essentially the whole network will be one big VPN.
>
> What is the reason/business case behind this? Do the benefits you gain
> really outweigh the drawbacks?
>
> Curious,
> Frank
>
>







More information about the Snort-users mailing list