Re: IPS (was: [fw-wiz] Sources for Extranet Designs?)

From: Gary Flynn (flynngn_at_jmu.edu)
Date: 02/28/04

  • Next message: Shimon Silberschlag: "[fw-wiz] Multiple small switches vs. a single big one; Granularity of control"
    To: firewall-wizards@honor.icsalabs.com
    Date: Fri, 27 Feb 2004 20:35:42 -0500
    
    

    Christopher Lee wrote:

    >I think the phrase "useless" could be a little hash in this case, consider
    >what IPS has been expected to do (not what Mr. Stiennon has defined)...
    >IPS has been pretty much been expected to weed out the known bad traffics on
    >your network, such as control/compartmenting the spreading of viruses. In
    >that scenario, it is not difficult for someone to code up a signature that
    >looks for these type of behaviour in a sequence of packets, which requires
    >no "real" packet/session reassembly. This approach, in my own humble
    >opinion, is no different than how most AV software looks for malware (not
    >viruses, which attaches itself to "any" executables) these days.
    >Obviously, this approach has its own shortcoming (just ask the Exchange
    >administrators who lost their information store database to poorly
    >configured AV software).
    >
    Kind of a side note to your example:

    Virus handling is best done on a device that proxies an actual SMTP
    server. If you block or drop an SMTP session at a lower layer in the
    middle of an SMTP transaction due to one message containing a virus,
    it may queue up on the sending mail server and block all messages
    behind it for quite a while.

    Also, and I speak from experience, if you drop worm carrying packets
    with an IDP when they're coming in hot and heavy, you better send a reset
    to the server to tear down the session or the number of open SMTP
    sessions will do bad things to the server. :)

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Shimon Silberschlag: "[fw-wiz] Multiple small switches vs. a single big one; Granularity of control"

    Relevant Pages

    • SMTP Connector
      ... Under mu smtp default server I keep having people connected under my current ... session. ... Is this correct or am I getting used as a relay? ...
      (microsoft.public.exchange2000.protocols)
    • RE: SMTP Server remote queue length alert
      ... Thank you for posting in the SBS newsgroup. ... automatically creates a SMTP connector for outgoing messages. ... bridgehead defines the Exchange server which can use this SMTP connector to ... What method is used to send outgoing email (DNS route or ISP ...
      (microsoft.public.windows.server.sbs)
    • RE: Exchange, BadMail Folder
      ... always growing after you have removed files from folder and unplug server ... Furthermore,Please refer to the following KB article to clean up the SMTP ... click SmallBusiness SMTP Connector under ... them in a single queue for the SmallBusiness SMTP Connector or for the one ...
      (microsoft.public.windows.server.sbs)
    • RE: SMTP error (only from Outlook)
      ... This issue appeared on specify user or all SMTP clients? ... If yes, in Exchange System ... Is there any local bridgehead server listed in "Local ... to over three dozen open relay block lists. ...
      (microsoft.public.windows.server.sbs)
    • RE: Email messages stuck in unreachable destination queue
      ... you configure sharing an SMTP address space in Exchange Server 2003 thru ... it seems like you do not block the open SMTP relaying ... on the Exchange server. ... To check the properties for the SmallBusiness SMTP Connector, ...
      (microsoft.public.windows.server.sbs)