Re: [fw-wiz] Firewall Placement Question



I would look into PacketFence or Branford Software's Campus Manager. I used it while doing work in the Uni environment.

http://www.bradfordnetworks.com/products/overview.html
http://www.packetfence.org/

The biggest thing you failed to include in your comment was policy. How are the policies written for the students. What TOS' are in place for resnet use. You shouldn't expect a client NOT TO use P2P if they haven't been implicitly told "Terms of use legalese wording goes here states thou shall not use P2P on our network" (remember the student's tuition payments pay your salary (technically) so think of them as clients and not students). Policies go a long way when it comes time to cut off connections.

What should be done is control on all levels. What is the environment like, collapsed core, three tiered (access, distribution, core). Placing an IPS won't necessarily alleviate/resolve your issues. So you place an IPS and 20 firewalls in my way to block me from using P2P... I decide to tunnel, then what?

Look at how your network is designed and take excerpts from standards, and best practices: (Cisco SAFE... while not the epitome of what I would particularly call SAFE... Its a baseline) http://tinyurl.com/29cfto

Personally I'd start with re-vamping policies so no clients cry foul when you place them on a VLAN to nowhere. There is a lot you could do without a firewall and (uberBuzzworded) IPS if the design was carefully looked at, re-designed and deployed. Something I always refer to from Cisco CCSP studies "Secure Monitor Test Improve" in this case - Monitor (see what's going on) Secure (make the necessary changes you need to make) Improve (improve on those changes).

As for the answer to the buzzword hype... IPS = overrated. Placement... Depends on your network. If you're using Cisco routers and they can handle it, depending on what kind of network your running, (Collapsed Core, etc.) you could get by with some crafty CBAC's, VLANs to knowhere, syslog, some expect scripts. Get creative ;) ... I made myself a VoIP IPS using syslog and expect... Impressed myself for two minutes real world means little, my network differs from others.

--
====================================================
J. Oquendo

SGFA #579 (FW+VPN v4.1)
SGFE #574 (FW+VPN v4.1)

wget -qO - www.infiltrated.net/sig|perl

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xF684C42E

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Relevant Pages

  • Re: IPS, alternative solutions
    ... I have the impression that some of the alternatives to IPS you mentioned ... Parts of the market have matured (network ... implementations (in-line protocol decoding and blocking/active response ... an often deployed technology at this time is ...
    (Focus-IDS)
  • RE: ASIC Based IPS
    ... IPS performs on each network stream can be done in parallel, ... There are 2 ways to achieve parallelism: ... The benefits of speed come about when you start using ASICs in parallel ...
    (Focus-IDS)
  • NADS ( was RE: IPS comparison)
    ... One thing that does bother me is how IPS has been ... great at the perimeter or other "choke points" in the network. ... NADS gives much of the value of traditional network ... that detection by itself is just not enough. ...
    (Focus-IDS)
  • RE: Network hardware IPS
    ... Subject: Network hardware IPS ... > Intrusion Prevention and Traffic Shaping Technology to: ...
    (Focus-IDS)
  • RE: NIPS Vendors explicit answer
    ... this is the only comprehensive independent IPS test that's been ... Make sure the product continues to block attacks when simple, ... Test the IPS like you would any other network element (switch, ... The other vendors waiting for my tests:) are Netscreen IDP,RealSecure ISS Proventia G200 and Network Associates NAI Intruvert 2600 series. ...
    (Focus-IDS)