Hi @Steve, :-) inline below.

On Wed, Feb 15, 2012 at 6:03 PM, Steve Muchai <smuchai@gmail.com> wrote:
On Wed, Feb 15, 2012 at 4:43 PM, aki <aki275@gmail.com> wrote:
> @Dennis, IMHO. This and all other useless-belong in the garbage tin- Open
> Source egde security systems cannot handle "dark networks", ever followed

Aki,
Previously I've successfully blocked P2P, skype and bittorent traffic
using pure open-source - DPI with application-level signature
detection using Snort, feeding rules to iptables on Linux. I know it
works even better now than it did then. And that's not the only way it
can be done, open-source.

That was ages ago, mostly for fun and is definitely not the way Tusker
wants to go. He's indicated that he needs a easy-to manage,
well-supported commercial solution.


P2P and the rest have or are gone stealth, from the old days and now is a big change. Wikileaks and what followed later changed many things. In these times, how would you detect encrypted traffic on port 80 or 8080 without running a proper DPI. And trust me, even the core networks out there that make our networks look like kijiji networks,   are facing very complex issues and DPI overheads. Some of these are running into Terabits DPIs that run distributed services. 

 

> There is a special need, and this need can only be partly implemented at
> core networks as an ISP or Gateways.
>
> Edge solutions can even simply run on a cisco router ALCs, why force end
> users to add other products?

Bad idea. Not at the core.
Back in my ISP days we had ACLs that blocked well-known bad traffic -
NetBIOS, known worms etc. at the edge.  But you'd just pointed out -
correctly - that such traffic will get around ACLs.

The answer is managed services for customers who want their traffic
managed for them - and this at a fee. Where the device that handles
this sits, is debatable. Should be it a CPE? Maybe. Or somewhere in
the provider network? I can't say. Some customers don't want the ISP
to touch their traffic.

One size doesn't fit all.

Regards,
Steve
_

Managed IP services such as QOS/IDS/NTM is a must have and ISPs, Telcos need to embrace this. No one on edge networks is going to micro-manage a problem such as Torrents which keep changing their patterns when threats increase to their survivability. Even if some taka taka Open source freeware worked, it cannot keep up with the changes as itself becomes a bottleneck. Let ISPs and Telcos offer secure and managed services, and the clients will not spend much on hardware. Ofcourse, the managed services are a VAS thus offered as such. 

Cheers. :-)