Originally posted by Vulcan
Lada, you might play with a bit Cisco gear, but don't try and BS me about what you do and don't know about.
I dont know much about T backbones, i never saw them.
But im sure that we will not see any IP filters on them in near future. Since they have their own problems with plain routing of packets.
Well if you never ever saw Snort or some other L7 filtering toys on Gbsp network, then you probably didnt see everything did you ?
Last month i were messing around project.
Firewall cluster with expected load of 2.5Gb/s. That firewall cluster provide HTTP filtering, SMTP filtering, FTP filtering, SSL hub + classsic l4,3 firewalling. If you still thing that connection inspecion is immposible in Gbps networks, let me know why please.
No centralized rules are impossible, since internet is not centralized network.
Consolided rules ... you mean like all big ISP shall implement those rules. Lets say that midsize ISP should be filtering ? Do you think that it could be cheaper that provide filtering as close to the last mile as possible ?
Now you might tell how did i confuse you before. I realy didnt get it this time.