On 12/29/05, Michael J. Semaniuk <[EMAIL PROTECTED]> wrote: > This has always been a problem, but I've found that using an IDS load > balancer does a lot to optimize packet inspection for promiscious devices. >
If you'd like to try building a commodity HW/SW solution to inspect and/or collect packets based on characteristics like IP address, IP protocol, or port, check out my post on using Pf dup-to to build a distributed traffic collection system. http://taosecurity.blogspot.com/2005/07/distributed-traffic-collection-with-pf.html Sincerely, Richard ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more. ------------------------------------------------------------------------
