RE: IDS on a load balanced BGP network
From: SEdwards@toplayer.comDate: 09/06/02
- Previous message: Chris: "Re: Load balanced routers and IDS"
- Maybe in reply to: Ian Macdonald: "IDS on a load balanced BGP network"
- Next in thread: seastham@na.cokecce.com: "Re: IDS on a load balanced BGP network"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: SEdwards@toplayer.com To: ccalvert@securedaemon.net, secids@dirk.demon.co.uk Date: Fri, 6 Sep 2002 07:22:04 -0400
Chris is right, we can certainly help.
If you take SPAN ports from your two routers and run them back into one of
our IDS Balancers then the balancer will re-augment the traffic before
passing it to the IDS. The challenge you have is if a data stream is split
between the two ISPs (so half the packets come from one ISP, the other half
from the other) and you connect an IDS to each router - then you could have
an attack split between the two IDS's such that neither see the real attack.
Using the IDSB you can feed in data from anywhere in the network (switches,
taps, asymmetrically routed networks etc.), and the balancer will organise
the flows - so that each complete flow is sent to the same IDS.
In addition we can also add a lot more functionality not seen in sensors,
like High Availability and Redundancy
Let me know if you would like more info
Regards
Simon
________________________________________________
Simon Edwards
Technical Evangelist
Top Layer Networks
US Office : + 1 508 870 1300 (x230)
US Mobile : + 1 617 953 8764
UK Office : + 44 1483 243 549
UK Mobile : + 44 7971 959170
www: www.TopLayer.com
email: sedwards@toplayer.com
"Perfecting the Art of Network Security"
----------------------------------------------------------------------------
--------
-----Original Message-----
From: Chris Calvert [mailto:ccalvert@securedaemon.net]
Sent: 05 September 2002 14:41
To: Ian Macdonald
Cc: focus-ids@securityfocus.com
Subject: Re: IDS on a load balanced BGP network
Hi Ian
Comments inline:
On Wed, 2002-09-04 at 10:22, Ian Macdonald wrote:
> Has anyone ever come up with a solution for running a IDS system on a BGP
> network.
TopLayer might be a solution for this. You can mirror the flow from
both connections.
http://www.toplayer.com/Products/ids_balancer.html
Hook up your IDS sensors of choice, and away you go!
Regards,
Chris
- Previous message: Chris: "Re: Load balanced routers and IDS"
- Maybe in reply to: Ian Macdonald: "IDS on a load balanced BGP network"
- Next in thread: seastham@na.cokecce.com: "Re: IDS on a load balanced BGP network"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|