Re: Gateway IDS

From: r00t@online.ie
Date: 06/25/02


From: <r00t@online.ie>
Date: Tue, 25 Jun 2002 11:35:00 +0100
To: Jochen Vogel <jvogel@it-sec.de>


> since last year i search a working gateway IDS solution.
> i search a solution that work like a firewall but additionally
> can block packets after an correlation with IDS signatures.
> the solution to send RST packets or reconfigure a firewall
> is nice but not really about latency or spoofing packets.

Hi Jochen,

I have deployed many IDS solutions similar to your needs. I would need more
specific information in order to gurantee it's exactly what your looking for.

You my have already checked it out but:

ISS RealSecure works quite well with Checkpoint Firewall 1, there are
actionable options available per signature including the ability to send RST's
to attacker hosts.

This is possible via the Checkpoint Opsec connector, there are limitations with
this configuration which you should be aware of before deploying.

You will also need a TX/RX span port on the switch in order to acheive this, or
you could use taps.

Hopefully this helps, if you need more info mail me off-list.

Cheers

./Mark

>
> greets
> Jochen
>
>



Relevant Pages

  • Re: iptables and dhcp
    ... > the same physical network segment as the firewall and the remote DHCP ... You used INPUT and not FORWARD chain ... # This target allows packets to be marked in the mangle table ...
    (comp.os.linux.networking)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: Visnetic and 8signs firewall LOOPHOLE Read....
    ... I said I am just reporting bug in your Firewall, ... From the Port Scan/Properties control screen: ... The firewall filtered 100% of the packets that were received. ... operating system (I'm talking Windows, ...
    (comp.security.firewalls)
  • Re: strange network traffic
    ... Maybe not so wise to not have a firewall and trust a third party lurker to ... Subject: strange network traffic ... > -> connection established, following packets have neither SYN nor ...
    (Security-Basics)
  • Re: port 80 is open
    ... The firewall drops all packets initiated ... > internet the ISP router does not send the unreachable message. ... and then close the connection as your IP is seen as not connected. ...
    (comp.security.firewalls)