@Sam, nice writeup. Hope it also helps @Tusker know indepth what he is facing in the fight against torrents.
Aki,
If i may be bold, and answer...
Most of the products put across here (CheckPoint, Sonicwall, Cyberoam, ASA) all come with a subscription service that downloads / updates rules for IDS, Packet inspection, Anti-Spam etc.
These updated rules, tied together with AD integration and User-based reporting, will ensure that the customer has the best protection, while getting reports and visibility into the network.
The customer will not need to have RHCE,LPI certification to operate/configure.
All these features in one product MUST surely cost money.
Most of these products actually run on Open source platforms (Cyberoam, Sonicwall run a Linux kernel)
I have not seen any free Open source product that can bundle all the features of an IDS
Am currently evaluating Endian firewall Community
http://www.endian.com/us/community/download/
Download:
http://sourceforge.net/projects/efw/files/Development/EFW-2.5.1/EFW-COMMUNITY-2.5.1-201201261800.iso/download
Regards,
./Sam