Re: Isakmp and Snort?

   As Bob sed you need unencypted traffic for a proper analysis of the
streams. Since esp encapsulates in encryption the data stream well
you really won't know it is good or bad until snort can read the data
revealed. Sort of speak anyways..
dreamwvr@dreamwvr.com wrote:

> > hi,
>       Well i always thought that as well till i read the netbsd ipsec page and
> how esp is not what some percieve it to be per se.. My plan was to set in my
> lab a netbsd client to a openbsd server host to host.. noticing that syntax was
> a bit diff i thought there might be a few gotchas.