logo       

Re: High availability design of NIDS: msg#00028

security.ids

Subject: Re: High availability design of NIDS

On Tue, Feb 22, 2005 at 03:47:03PM -0600, Michael Allgeier wrote:
> OpenBSD + CARP + snort = failover NIDS

Only partially true -- CARP will only allow you to do IP failover. But
that won't help you if, say, the snort process dies or is otherwise
unreachable. That situation should be fairly rare, but it is something
to consider.

-jon

--------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
--------------------------------------------------------------------------




<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise