Re: [fw-wiz] Thoughts on the new Cisco ASA 5500 firewalls

From: ArkanoiD (ark_at_eltex.net)
Date: 05/20/05

  • Next message: Chuck Swiger: "Re: [fw-wiz] A fun smackdown..."
    To: Tichomir Kotek <tichomir.kotek@lynx.sk>
    Date: Fri, 20 May 2005 19:09:00 +0400
    
    

    Well, the obvious conclusion is that what it does filter and what it does
    detect by IDS are not exactly the same data stream because of implementation
    issues.

    On Fri, May 20, 2005 at 12:32:55PM +0200, Tichomir Kotek wrote:
    > Chris Byrd wrote:
    > > I just spoke with a Cisco sales rep about this. According to him, the
    > > ASA 5500 is running the same OS as the latest Pix FWs (7.0), with the
    > > other stuff bolted on top. It is also running the same ASICs as their
    > > IPS devices. That does make me feel a *little* better about this, but
    > > I do still need to eval one in person.
    >
    > actually IDS/IPS is handled in separate module, where you can "route"
    > traffic flows for inspection, so at least this do not overload central CPU.
    >
    > tk
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    >
    > email protected and scanned by AdvascanTM - keeping email useful - www.advascan.com
    >
    >
    >

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Chuck Swiger: "Re: [fw-wiz] A fun smackdown..."

    Relevant Pages

    • RE: IDS event filtering
      ... I think there are a few ways to filter; ... at in over a year so not sure if any backend IDS correlation. ... Deprioritize alerts on ... > Find out quickly and easily by testing it with real-world attacks ...
      (Focus-IDS)
    • Re: IDS event filtering
      ... I won't filter out anything. ... does not guarantee anything (e.g. you know you do not have MSSQL ... > ingress - egress firewall rules, IDS configs, or whatever. ... > IDS sensors. ...
      (Focus-IDS)
    • Cisco IDS 4210 Follow-up questions
      ... A few weeks ago I posted asking for documentation links on the IDS ... want to exclude it for the destination and source IPs I am seeing. ... If I do a filter and put a subSigID in and teh same settings as above ...
      (comp.dcom.sys.cisco)
    • Re: IDS event filtering
      ... > I am wanting to get an idea of what you guys out there filter from your ... > IDS sensors. ... Some of the sensors I monitor get TONS of events for MSSQL ... > have any SQL services on the internet, is it safe to filter out those ...
      (Focus-IDS)
    • Re: Question about Matlabs implementation of Welch PSD when window size is larger than NFFT
      ... pwelchis useful when the data stream is too long to be processed "in one ... shot". ... An alternative is to filter and decimate the power spectrum estimate. ...
      (comp.dsp)