Since v5 gets more and more stable now, I'm thinking about upgrading our v4.021.
One major reason is the Intrusion Detection Feature.
I just wanted to know your thoughts about this, since I had a presentation on "Packet Alarm" yesterday.
They told me, that it's not an good idea to put both packet filter and intrusion detection an a single machine. It would take too much CPU time and slow down the firewall (we have an average of 2% on our ASL 4.021

Furthermore Packet Alarm features an automatic vulnerability scanner, auto prevention and detects anomal network traffic.
I'm kind of new to this stuff, so I would like to know, whether the ASL solution is sufficient for our small network (
This thread was automatically locked due to age.