-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Look at the features and figure out what fits your needs.  They each
have there strengths and weaknesses.. ALSO, don't rule out NFR.

Carric's Opinions:

Net Prowler:  Have they released a truly distributed architecture
product (i.e. you can manage a lot of them from one place)?  Do they
have any susceptibilities to attack or does the installation
procedure help lock down the machine?  What platforms does it
"require" and do those all fit into your architecture (or are you
going to have to hire a Solaris expert to run it?)?  In short, I was
not all that happy with NetProwler when I looked at it overall.. it
does some cool things, and it's cheaper than some of the others, but
my gripe about Axent (and NAI for that matter) is they have 5.10e27
products, and none of them integrate with the others.... NO
integration.

NAI:  Are we still talking rev 1.0?  Will you get support AFTER you
buy the product?  Is NAI really a  network security company??  If you
do your research on NAI, one common complaint from their customers is
that you can't get any customer service after you purchase the
product.  I tried for months to get an eval of cybercop on site, and
was stonewalled.  They eliminated themselves from the product
selection pool right away.

Cisco:  Expensive, hard to setup, hard to make changes, and you MUST
run a Solaris brain for IOS based engines.  While I have no personal
problems with Solaris (other than it's an impotent, useless OS out of
the box, and good for nothing unless you either spend $7.6e23 on
additional software or go get all the GNU stuff for it), they don't
exactly give the hardware away, and you may not have the on-site
expertise to manage it.  They keep talking about an NT version of the
engine, but I haven't seen it yet.

NFR:  Great product, dead easy to deploy (insert CD, turn on power,
answer about 12 questions, done - they also have black-box engines,
and you can spit out a config diskette for your remote sites, and if
you have to have  one rebuilt, it's as simple as getting someone
(even if they are severely technically challenged.. hey, grandma
could handle this) to pop in that diskette, flip the power switch and
then tell them thank you, that's all you need.  It is also one of the
better IDS's, AND I really feel it will be a major contender at the
enterprise level in the not-so-distant future.

ISS:  My personal favorite.  Suffice it to say, I feel it's the ONLY
solution right now for a large enterprise.  You can have a "meta"
engine called Decisions that correlates all the data, and does trend
analysis and reporting for you after you have fed it all the data
from all of their tools (RealSecure, Scanner, System Scanner, DB
Scanner, etc.).  They are the only ones with this level of
integration right now.  Also, RS is easy to deploy, a delight to
manage and monitor, and usually takes first place when all the IDS's
are pitted against each other when all products are evaluated as a
whole.  The Mgt Console is easy to read, you don't have to load a
client to manage a mgr to manage your engines, etc.  Install the
console on your workstation, and then deploy your engines, do the key
exchange b/t console and engine, and you are up and running.  You get
10 or so initial profiles for your engines whether it's in the DMZ or
jus monitoring for Attacks (you can copy the stock configs to a new
config, and then modify it for your network too).  ISS stays withing
their core competency which I like.  They are not trying to be a one
stop net security

This is getting entirely too long...  I'll go ahead and end the pain
here.

Carric Dooley
Network Security Consultant

"I have often regretted my speech, never my silence." 
- - Xenocrates (396-314 B.C.) 



- ----- Original Message ----- 
From: "Ivan Fox" <[EMAIL PROTECTED]>
To: "BUGTRAQ" <[EMAIL PROTECTED]>; "Firewall-1"
<[EMAIL PROTECTED]>; "Firewalls@Lists. Gnac.
Net" <[EMAIL PROTECTED]>; "Firewall-Wizards@Nfr. Net"
<[EMAIL PROTECTED]>
Sent: Tuesday, June 13, 2000 10:03 AM
Subject: [FW1] OT - Axent Intrusion Detection


> 
> We are looking for an effective Intrusion Detection program.  We
> are introduced to ISS Intrusion Detections, Network Associates'
> Cypercop and Axent's.
> 
> Any comments/suggestions about these products are much appreciated.
> 
> Ivan
> 
> 
> 
> ====================================================================
> ============ 
>      To unsubscribe from this mailing list, please see the
> instructions at 
>                http://www.checkpoint.com/services/mailing.html
> ====================================================================
> ============ 

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.3 for non-commercial use <http://www.pgp.com>

iQA+AwUBOUZf3VUqWOkDpMZ2EQLEzwCfTQ635NQXqr+OVkNDXVIwop35YGMAliqL
MkxWMcVDI7qrnl0c/WBfxFM=
=6yT1
-----END PGP SIGNATURE-----




================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to