nanog mailing list archives
Re: Checkpoint IPS
From: "Roland Dobbins" <rdobbins () arbor net>
Date: Fri, 06 Feb 2015 01:11:24 +0700
On 6 Feb 2015, at 0:55, Matthew Huff wrote:
What if you are a hosting company and those aren't your servers to patch?
Then it isn't the operator's problem.
What about the time to patch 200+ servers versus configuring one location?
Operators should have sufficient automation to do this quickly. If not, they're Doing It Wrong.
What if you have to schedule the staff and maintenance window to patch the servers?
See above.
What if you have legacy equipment that you must continue using, but the vendor is slow to provide the patch.
There are other ways (reverse proxies, on-box systems like ModSecurity, et. al.); or take them offline.
----------------------------------- Roland Dobbins <rdobbins () arbor net>
Current thread:
- Re: Checkpoint IPS, (continued)
- Re: Checkpoint IPS BPNoC Group (Feb 08)
- Re: Checkpoint IPS Roland Dobbins (Feb 08)
- Re: Checkpoint IPS Colin Johnston (Feb 06)
- RE: Re: Checkpoint IPS Darden, Patrick (Feb 06)
- Re: Checkpoint IPS Colin Johnston (Feb 06)
- RE: Re: Checkpoint IPS Darden, Patrick (Feb 06)
- Re: Checkpoint IPS Colin Johnston (Feb 06)
- RE: Checkpoint IPS Raymond Burkholder (Feb 05)
- Re: Checkpoint IPS Roland Dobbins (Feb 05)
- RE: Checkpoint IPS Matthew Huff (Feb 05)
- Re: Checkpoint IPS Roland Dobbins (Feb 05)
- RE: Checkpoint IPS Matthew Huff (Feb 05)
- Re: Checkpoint IPS Roland Dobbins (Feb 05)
- Re: Checkpoint IPS Terry Baranski (Feb 05)
- Re: Checkpoint IPS Roland Dobbins (Feb 05)
- Re: Checkpoint IPS Joel Maslak (Feb 06)
- Re: Checkpoint IPS Michael Hallgren (Feb 05)
