What is the network installation configuration of the NetScreen-IDP?
There are two major installation configurations for the NetScreen-IDP: sniffer and gateway mode. There are three modes of gateway operation, bridge mode, proxy-ARP mode and router mode, that differ based on how the device forwards packets. Gateway modes enable active responses, which means a security device can actually prevent attacks by dropping packets or connections, so that they never reach their intended “victim.” The alternative to a gateway mode is sniffer mode. In sniffer mode, the device operates similar to a traditional intrusion detection system, acting as a passive observer of the network that provide only limited and less reliable methods to respond to detected attacks. Customers that deploy NetScreen-IDP in sniffer mode will not receive the benefit of the system’s active prevention capabilities, however, they will be able to take advantage of the accuracy and simple management of the device.