Re: IPS - Cisco vs. McAfee vs. Tippingpoint Jul 30 2009 01:58AM
I've had bad experience with the McAfee sensors. Total crap. You can only filter by IP address, not ports too. One example is if you have an http server on a nonstandard port, your only option is to deal with the alarm or compeltely disable it entirely or for the IP address. You can't say HTTP is okay on this port but not others.

I also noticed that if you enable traffic logging, it doesn't always capture packets. It also doesn't always list a source or destination IP. It's been about a year and a half but man I hated the Intrushield!

In their defense, they *may* have changed things drastically in the past year and a half. And I hope they did!!!

Network Sentry

