[177799] in North American Network Operators' Group
Re: Checkpoint IPS
daemon@ATHENA.MIT.EDU (Roland Dobbins)
Thu Feb 5 14:59:49 2015
X-Original-To: nanog@nanog.org
From: "Roland Dobbins" <rdobbins@arbor.net>
To: nanog@nanog.org
Date: Fri, 06 Feb 2015 02:59:26 +0700
In-Reply-To: <CACAVgUzkAX6yN4vgxWysuyqdVyHjHR7qgGG-WKpyZUXb6-=29A@mail.gmail.com>
Errors-To: nanog-bounces@nanog.org
On 6 Feb 2015, at 2:26, Terry Baranski wrote:
> Zero, on my networks.
Which highlights the importance of broadness of experience, of knowledge
and understanding of the experiences of others, and understanding of the
implications of scale.
> If you can't deploy IPS's in such a way that they don't make your
> network
> less secure via DDoS susceptibility, or reduce availability due to
> non-existent or subpar redundancy/survivability engineering, then you
> shouldn't deploy IPS's.
By their very nature, it's impossible to do so.
-----------------------------------
Roland Dobbins <rdobbins@arbor.net>