This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS as WAF?

One of the new (as of last week) PCI DSS requirements is to have a "WEB Application Firewall" (WAF)...

I know that some IPS's count; but what Astaro would officially say as to that?

My understanding is that the IPS would need to protect against at least some of the OWASP top ten, e.g. XSS, SQL/code injection, ...
http://www.owasp.org/index.php/Top_10_2007

Thanks
Barry


This thread was automatically locked due to age.