[Snort-users] Comparison question

Kevin Johnson kjohnson at ...12400...
Sun Feb 27 18:23:37 EST 2005


On Sun, 2005-02-27 at 20:24, Shaun T. Erickson wrote:
> I am wondering if anyone can give me any idea as to how well, or not, a 
> Snort installation (of whatever is latest) would compare to using the 
> IDS/IPS features of my SonicWall firewall (a Pro 4060, running their 
> latest firmware). I have the firewall, with those features licensed. I 
> could set up Snort. I'm trying to decide the merits of either decision.
> 
>     -ste

Hi-

First, I assume that you know that you will be told Snort is better on a
snort-users mailing list.<g>  But in all seriousness I would run both. 
If you have the resources to manage two different IDS solutions, it can
only be a good thing.  Just like most of us run multiple anti-virus
solutions on our mail servers, two different IDS's will better alert us
to nefarious activity.

Hope that helps,
Kevin
-------------------
BASE Project Lead
http://sourceforge.net/projects/secureideas
http://base.secureideas.net
The next step in IDS analysis!
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20050227/0335ee20/attachment.sig>


More information about the Snort-users mailing list