Re: [fw-wiz] Integrated IDS/IPS/Firewall (Cisco ASA and Juniper ISG)



nuqneH,

Actually Cisco ASA (don't have expirience with Juniper) is not a "single box".
Think it as PIX with IDS box with some kind of proprietary network interface
between them (actually it does even have MAC address ;-).

I don't like CISCO IDS though (and PIX itself is not much better, both
are functionally impaired) ,
but using products from the same vendor provides some management and
reporting unification that may be considered major advantage.

On Wed, May 24, 2006 at 11:11:56AM -0500, Robert A Beken wrote:
I have a question for the group about this new trend of using a single
firewall for all IDS and Firewall related tasks in an integrated box for
enterprise organizations (not SOHO). I personally think it's a bad idea
and lacks flexibility in configuration and "defense in depth" posture
towards security. What are other people's thoughts?

Thanks and Regards,


Robert Beken CISSP, GCFW
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Monitoring Servers
    ... An IDS system on the outside of your PIX is rather pointless (especially if ... it's the "IDS" that comes with the PIX), since you're not seeing what gets ... honeypot inside the network, make sure it's a dark host (has no legitimate ...
    (microsoft.public.security)
  • Re: [fw-wiz] Cisco Pix-IDS Blocking
    ... You will need a more recent IDS image. ... a change which warranted a matching change on the IDS ... I've recently deployed a Cisco Pix 506 ... >doesn't seem to send the shun commands. ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Thoughts on the new Cisco ASA 5500 firewalls
    ... From what i know looking PIXen inside and outside, IDS module is packet capture ... > Cisco is marketing the ASA 5500 appliances as PIX, VPN Concentrator, Secure ...
    (Firewall-Wizards)
  • RE: [fw-wiz] Thoughts on the new Cisco ASA 5500 firewalls
    ... Cisco is marketing the ASA 5500 appliances as PIX, VPN Concentrator, Secure ... IDS, and network anti-virus in a single box. ...
    (Firewall-Wizards)
  • Cisco pix IDS feature question
    ... We have cisco pix 515E now we want to turn on the IDS feature to block ... IDS has about 60 signatures for example detecting Fyn scans. ... when those attacks passed before enabling the IDS? ... if its dropped packets and the traffic sure passed throw the ...
    (comp.dcom.sys.cisco)