Re: Newbie IDS questions

From: Andrew Plato (aplato@anitian.com)
Date: 01/11/02


Date: 11 Jan 2002 02:38:11 -0000
From: Andrew Plato <aplato@anitian.com>
To: focus-ids@securityfocus.com


('binary' encoding is not supported, stored as-is)

In-Reply-To: <9DCB77D01366AA4497DAFA759E1EB580BFAC33@WW1WEX01>

>The idea that has been proposed is to put the IDS in
> the path between connections,
> rather than connected in promiscuous mode.

BlackICE Guard does exactly this. Its the BlackICE
IDS on a dual interface system. Traffic enters one
interface, gets IDS'ed, and if an intrusion is seen,
blocked. "Safe" traffic exits the other interface. See:
http://www.networkice.com/products/blackice_guard.
html

We sell these as appliances and have quite a few in
the feild protecting AIX and UNIX boxes. With the right
tweaking, they are very powerful.

But they are not a replacement for a firewall. You
should still have a good firewall.

Andrew Plato
President / Principal Consultant
Anitian Corporation
www.anitian.com



Relevant Pages

  • Re: New to IPFW and would like critique...
    ... The firewall ... You log a *lot* of types of connections that aren't particularly ... > # Outside interface network and netmask and ip ... packet coming from a port 53 and going to, say, port 137. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: NAT with IP Filters
    ... Static NAT (inbound) connection on purpose. ... you have disabled the firewall if you aren't filtering specific ports. ... interface, but this is far more tedious than simply telling the routing ... are fine except that they don't allow outgoing connections via e.g. TCP ...
    (microsoft.public.windows.server.networking)
  • Re: NAT with IP Filters
    ... connections which I mean, from a private interface). ... Static NAT connection on purpose. ... you have disabled the firewall if you aren't filtering specific ports. ...
    (microsoft.public.windows.server.networking)
  • Re: SP1 breakes VPN RRAS Server
    ... And it's like I wrote in the previous message: The VPN server doesn't accept any connection to the firewalled interface over any protocol, including a telnet session to this interface over PPTP port 2723 ... firewall" category, the server doesn't accept inbound connections anymore, ...
    (microsoft.public.windows.server.networking)
  • PLEASE HELP - trying to forward web traffic through firewall w/ IPTABLES
    ... and iptables on the firewall. ... an external Internet ethernet interface. ... # accept all mail connections on any interface for Sendmail/PostFix ... accept everything except from the Internet-facing interface) ...
    (comp.os.linux.networking)