What are the limitations of a network based IDS?
A network based Intrusion Detection system has 2 big limitations: Switched networks – A network based IDS must be able to see all network traffic of the network that it is protecting. If a network uses a switch (most do nowadays) a sniffer will not be able to see all the network traffic. This usually means that you would deploy a network based IDS at the gateway only, i.e. on your Internet connection. However this does not protect you from internal attacks. High Speed – Modern networks are so fast, that an Intrusion Detection system has a hard time keeping up.