Compare cert salaries and plan your next career move
Bl8ckr0uter wrote: » Meh. I did think of that. I kind of want dedicated appliances. This is strictly NIPS. If I were looking for HIPS I would probably look for something like that. If I remember correctly, Sourcefire is in the top of the Gartner Magic Quadrant.
docrice wrote: » My impression based on hearsay is that the Cisco IPS modules are not speed demons. If you have a lot of traffic running through the ASAs and you need to maintain a given service level, they're probably not a good choice.
Bl8ckr0uter wrote: » That's exactly what I am looking for. Arrggg. I just hope the sourcefire gear isn't two pricey.
Zartanasaurus wrote: » On the lower end, you can get a 1.5 Gbps IPS for ~60K. On the higher end, with 10Gb SFP ports, high 1gb port density with redundant devices, you'd be looking to pay around $300K. What is your budget and what is "too pricey" to you? What are your requirements?
Zartanasaurus wrote: » Those are Tipping Point quotes. My potentially bad assumption is that SourceFire would be in that same ballpark for competitive reasons.
Zartanasaurus wrote: » Overall impression I got after all these demos is that Cisco is way behind on the times when it comes to their security offerings.
docrice wrote: » One of the bigger selling points of (HP) TippingPoint and Sourcefire is that they invest heavily in their vulnerability research teams. I don't know how other competitors in the space such as Cisco, Check Point, Juniper, Top Layer, etc. do in this regard.
docrice wrote: » Taking the SANS 503 course will help gain some insight into what to look for in an IDS / IPS. Chop chop.
docrice wrote: » Huge concerns for these kinds of prevention devices are 1) falsing, 2) tuning ability for profiles, configuration parameters, etc., 3) signature writing, 4) latency, 5) over-subscription of the interface and how the appliance behaves in those conditions, 6) reporting, and 7) the compliance checkbox. Granted, the last one most of us techies don't care about too much as that's more of a management requirement.
docrice wrote: » There's a Palo Alto show-and-tell next week in their Santa Clara office that I'll be attending. It should be interesting. I'm also looking into various vendors at the moment for these kinds of devices and I have a feeling it'll come down to "the expensive brands."
Bl8ckr0uter wrote: » Sourcefire is in the top of the Gartner Magic Quadrant.
Forsaken_GA wrote: » Rule #1 when it comes to purchasing decisions - Gartner is a 4 letter word. Take anything Gartner says with a grain of salt, their Magic Quadrant is very far away from an objective look at the industry.
Bl8ckr0uter wrote: » Seriously? I thought Gartner and NSS were pretty good.
Bl8ckr0uter wrote: » Cuss that's alot of money (to me anyway). I think I might just give them a call to get a ball park (and see if its worth the time). It is a very real possibility that he may want to see some cisco 4200 series prices as well (which would be dope since I am tasked with going for the CCNP:S ) Besides effectiveness and throughput what other things should a good IDS/IPS be judged on? I mean I have never done this before, and I feel like I am not taking things into consideration. I have been reading magic quadrants for IDS/IPS gear and some NSS test reports and honestly I have been going based off of those. What other considerations did you think about when going for an IDS/IPS for an enterprise (if you don't mind me asking)? I like Palo Altos man. The CLI is very easy to learn and the capabilities are just super dope. I really like the reporting. I deployed one on our wireless network in the morning and by the afternoon I found two torrenters, a couple dropboxes and a ton of facebook traffic. Excellent kit. That's my impression as well. Did you see that Palo Alto is one of the reasons ciscos security sells fell last quarter?Palo Alto Networks is the culprit behind Cisco's -8.4% FY11 security sales decline - Brad Reese
higherho wrote: » I was curious if you thought of having a software based IPS / IDS like HBSS from Macafee E policy orchestrator? Also deploys Rouge Sensors Agents too.
Compare salaries for top cybersecurity certifications. Free download for TechExams community.