Re: IDS evaluation

From: Saad Kadhi (bsdguy@docisland.org)
Date: 08/22/02


Date: Thu, 22 Aug 2002 08:56:05 +0200
From: Saad Kadhi <bsdguy@docisland.org>
To: focus-ids@securityfocus.com

On Wed, Aug 21, 2002 at 04:04:07PM -0400, Elijah Savage wrote:
> I am coming to you experts for a little help. It has come time to renew our
> maintenance contract with cisco we have the old netranger product. Well my
> company wants me to do a review of 3 products of my choice to see what
> other products may provide us a better solution that what we currently
> have. We have 12 IDS sensors currently. Can you all recommend 3 products
> that will be worth my time to take a look at?
If central management/event correlation is what you need then my list would be:
1.Enterasys Dragon
2.Cisco Secure IDS
3.ISS

However, the new appliances from Cisco that promise better performance than
Dragon (among other things) are still vaporware at this time.

I'm a Snort fan but deploying 12 of them with central management needs good
expertise and multi-tool gluying skills.

-- 
Saad Kadhi 
[pgp keyid: 35592A6D http://pgp.mit.edu]
[pgp fingerprint: BF7D D73E 1FCF 4B4F AF63  65EB 34F1 DBBF 3559 2A6D]
# booth slave for hire



Relevant Pages

  • Re: IDS recommendations
    ... Subject: IDS recommendations ... commercial parties keep you up to date with new signatures and that they ... > Dragon and Cisco. ... > lean more toward Cisco. ...
    (Focus-IDS)
  • Re: IDS recommendations
    ... I have no real experience with ISS but here is what I can really say on ... Dragon and Cisco. ... Dragon requires more Unix admin expertise than Cisco.Cisco is very good in ...
    (Focus-IDS)
  • Re: IDS Players?
    ... Very good with a Cisco infrastructure and ver ygood with automated response. ... but not as much as Dragon or Cisco and here is why. ... Subject: IDS Players? ...
    (Focus-IDS)