On 12/29/05, Michael J. Semaniuk <mike_at_semaniuk.com> wrote:
> This has always been a problem, but I've found that using an IDS load
> balancer does a lot to optimize packet inspection for promiscious devices.
>
If you'd like to try building a commodity HW/SW solution to inspect
and/or collect packets based on characteristics like IP address, IP
protocol, or port, check out my post on using Pf dup-to to build a
distributed traffic collection system.
http://taosecurity.blogspot.com/2005/07/distributed-traffic-collection-with-pf.html
Sincerely,
Richard
------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------
Received on Jan 05 2006