RE: nCircle IP360

From: PIATT, BRET L (PB) (bp3847@sbc.com)
Date: 09/27/01


Message-ID: <1FD70EE03885D411B9AB00508BCFDEAC0419794C@msgsrv05.srv.pacbell.com>
From: "PIATT, BRET L (PB)" <bp3847@sbc.com>
To: "'Altheide, Cory'" <CAltheide@broadband.att.com>, "'focus-ids@securityfocus.com'" <focus-ids@securityfocus.com>
Subject: RE: nCircle IP360
Date: Wed, 26 Sep 2001 15:56:34 -0700


 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Personally I'd recommend Nessus. You can configure it to scan all
networks you are concerned with easily through cron, it produces HTML
based reports by host. With a couple of small shell scripts using
diff and a snmp package you could tie this into your NMS alerting you
each time the vunrabilities on a host changed from the known
configuration. Nessus is constantly updated by the security
community with new signatures so you don't have to rely on the
financial future of a small software vendor or the possible cost of
having to do all the updating internally. Nessus allows you to
connect to the server to configure scans through an encrypted client
session. With proper network design and security policy you don't
really need to have separate sensors on each network segment (IP is
routable for a reason).

Bret Piatt - Network Security Engineer II - CCNP-CCDP-SCNA-RHCE-MCP
SBC DataComm - Advanced Security Services Group

- -----Original Message-----
From: Altheide, Cory [mailto:CAltheide@broadband.att.com]
Sent: Wednesday, September 26, 2001 3:26 PM
To: 'focus-ids@securityfocus.com'
Subject: nCircle IP360
Sensitivity: Confidential

Does anyone have any experience with nCircle's IP360 product? (
http://www.ncircle.com/security/ip360.html ) From the sales pitch I
received, it sounds excellent. I am, however, interested in hearing
if anyone has any practical experience with this.

Thanks,

Cory Altheide
Internet Security Coordinator
AT&T Broadband Legal Demands Center
caltheide@broadband.att.com
(800)871-6298 x 72680
(720)267-2680
 

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.0

iQA/AwUBO7Jc+1+IxmqPU329EQKnAgCfe6FQxC7UQ9fcS1DFhhsnyeKnAmUAnAg+
eGKE+h/iFiVSLpsxL+Usun4Z
=qtfy
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: Security scan
    ... Our security guy was running a security scan using Qualys on ... due to a security scan by nessus. ... network, and the scan was run from a workstation inside the ... locked up a Solaris 2.7 box, three HP OpenView servers (two running Win2k3 ...
    (comp.sys.hp.mpe)
  • [kde] Nessus Plugin Feed
    ... If your Nessus installation can not reach the internet directly, ... [Passive Vulnerability Scanner] ... Watches network traffic 24x7 for new hosts, ... access and 3D visualization of security data. ...
    (KDE)
  • Re: kern/130605: [tcp] Certain hardware produces "Network is unreachable" errors for scanning tools
    ... Subject: kern/130605: Certain hardware produces "Network is unreachable" ... errors for scanning tools ... This suggests that Nessus is passing an unexpectedly high or low number ...
    (freebsd-net)
  • RE: [fw-wiz] commercial va
    ... Network infrastructure, particularly switches with spanning ... avoid routing your nessus scans around a lot, ...
    (Firewall-Wizards)
  • RE: MBSA 1.2
    ... I don't believe that Nessus scans for the presence of Windows patches. ... detected over a network link. ...
    (Security-Basics)