We've deployed this scenario on Linux + Free S/Wan running snort on all physical interfaces and all ipsecX interfaces for folks. The fastest wire-speed we've had on one of these deployments is T1, and a PIII450 has handled VPN traffic at wirespeed even with the added load of snort. Sorry I don't have any higher-bandwidth benchmarks for you.
-----Original Message-----
From: counter.spy_at_gmx.de [mailto:counter.spy_at_gmx.de]
Sent: Friday, November 29, 2002 4:20 AM
To: focus-ids_at_securityfocus.com
Subject: IDS on VPN-GW
Hi folks,
I have recently tested snort on a vpn-gateway that runs on linux (just for
testing purposes, no productive server).
Received on Dec 02 2002