Re: IDS on a load balanced BGP network
From: Omachonu Ogali (missnglnk@informationwave.net)Date: 09/05/02
- Previous message: Greg Shipley: "Re: IDS on a load balanced BGP network"
- In reply to: Greg Shipley: "Re: IDS on a load balanced BGP network"
- Next in thread: Ian Macdonald: "Re: IDS on a load balanced BGP network"
- Next in thread: J R: "Re: FW: IDS on a load balanced BGP network"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 5 Sep 2002 14:57:15 -0400 From: Omachonu Ogali <missnglnk@informationwave.net> To: Greg Shipley <gshipley@neohapsis.com>
On Thu, Sep 05, 2002 at 01:46:54PM -0500, Greg Shipley wrote:
>
> On Thu, 5 Sep 2002, Omachonu Ogali wrote:
>
> > BGP has nothing to do with this setup, generally your IDSes
> > should be located at the border of your network (your routers
> > connected to your peers and transit providers). So in this
> > scenario, I would place them behind each router connected
> > to each transit provider.
>
> Er, huh? If my IDS only sees part of the session, how is BGP *NOT* part
> of this?
If your packets are switching next-hops on every other packet,
then that is a separate problem you need to address if you
absolutely need next-hop consistency for this application.
Depending on how the network is numbered, you can announce the
networks for Datacenter A as you normally would, and then announce
Datacenter A's networks via Datacenter B, but with the AS path
padded a couple of times, the local-preference lowered, or both.
Vice versa for Datacenter B's network blocks.
> And how can you come to this conclusion without knowing his topology?
The next line you skipped said "if your network is laid out in
a core-distribution-edge topology". Even if he is operating a
collasped core where the core is handling both core and
distribution functions, that still remains the single entry
point into his network, for both his transit providers, peers,
and datacenter links, where he can place an IDS behind.
> -Greg
-- Omachonu Ogali Information Wave Technologies missnglnk@informationwave.net http://www.informationwave.net
- Previous message: Greg Shipley: "Re: IDS on a load balanced BGP network"
- In reply to: Greg Shipley: "Re: IDS on a load balanced BGP network"
- Next in thread: Ian Macdonald: "Re: IDS on a load balanced BGP network"
- Next in thread: J R: "Re: FW: IDS on a load balanced BGP network"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|