Re: Gateway IDS

From: Stacy Holbert (SHolbert@do.usbr.gov)
Date: 06/25/02


Date: Tue, 25 Jun 2002 08:32:49 -0600
From: "Stacy Holbert" <SHolbert@do.usbr.gov>
To: <jvogel@it-sec.de>, <focus-ids@securityfocus.com>

Check out OneSecure IDP. It's an in-line device that can drop packets
and kill sessions before they get to your hosts.

http://www.onesecure.com/

>>> Jochen Vogel <jvogel@it-sec.de> 06/24/02 02:14AM >>>
hi,

since last year i search a working gateway IDS solution.
i search a solution that work like a firewall but additionally
can block packets after an correlation with IDS signatures.
the solution to send RST packets or reconfigure a firewall
is nice but not really about latency or spoofing packets.

greets
Jochen



Relevant Pages

  • Re: iptables and dhcp
    ... > the same physical network segment as the firewall and the remote DHCP ... You used INPUT and not FORWARD chain ... # This target allows packets to be marked in the mangle table ...
    (comp.os.linux.networking)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: Visnetic and 8signs firewall LOOPHOLE Read....
    ... I said I am just reporting bug in your Firewall, ... From the Port Scan/Properties control screen: ... The firewall filtered 100% of the packets that were received. ... operating system (I'm talking Windows, ...
    (comp.security.firewalls)
  • Re: strange network traffic
    ... Maybe not so wise to not have a firewall and trust a third party lurker to ... Subject: strange network traffic ... > -> connection established, following packets have neither SYN nor ...
    (Security-Basics)
  • Re: port 80 is open
    ... The firewall drops all packets initiated ... > internet the ISP router does not send the unreachable message. ... and then close the connection as your IP is seen as not connected. ...
    (comp.security.firewalls)