Re: serial-line protocols

From: Raj Malhotra (ral.mal_at_gmail.com)
Date: 08/31/04

  • Next message: Richard Bejtlich: "Re: session logging IDS"
    Date: Tue, 31 Aug 2004 18:13:44 +0530
    To: Rob Shein <shoten@starpower.net>
    
    

    Hi,

    The network looks like this

    ----------------------------------
    ----------------------------------
    | ROUTER | -------PPP fiber link---| ROUTER |
    ----------------------------------
    ----------------------------------
           | |
    ------------------ ------------------
    | switch | | switch |
    ------------------ ------------------

    The constraints are as follows:
    1) cannot mirror/span ports on the routers
    2) cannot deploy NIDS at each switch

    we are left with the only option of tapping the PPP link.

    Raj

    On Mon, 30 Aug 2004 10:30:42 -0400, Rob Shein <shoten@starpower.net> wrote:
    > I would think you'd be better off deploying the NIDS at either end instead,
    > adjacent to one of the routers. Anything passing in between them (and not
    > generated by one of them, obviously) would have to pass by that position
    > anyways, would it not?
    >
    >
    >
    > > -----Original Message-----
    > > From: Raj Malhotra [mailto:ral.mal@gmail.com]
    > > Sent: Thursday, August 26, 2004 8:08 AM
    > > To: focus-ids@securityfocus.com
    > > Subject: serial-line protocols
    > >
    > >
    > > Hi,
    > >
    > > We have two routers connected by fibre running a serial-line
    > > protocol like PPP. If we need to deploy a NIDS running on a
    > > linux-box having a 10/100/1000 ethernet card, would an
    > > optical-tap with a protocol converter suffice?
    > >
    > > With a serial-line protocol would any synchronization at the
    > > protocol converter be necessary?
    > >
    >
    >


  • Next message: Richard Bejtlich: "Re: session logging IDS"

    Relevant Pages

    • Re: Misconceptions
      ... >> NAT can be implemented on many routers, but only on stub network (the ... usually a private/office network) routers. ... >> Routers are NOT firewalls. ... >> A NIDS is just that. ...
      (comp.security.firewalls)
    • Re: Misconceptions
      ... > True routers route traffic much like the old railroad turntables ... Firewalls implement security policies or rules ... > handled by anti-virus programs, which should be on the ... > A NIDS is just that. ...
      (comp.security.firewalls)
    • Re: Misconceptions
      ... I admit Firewalls and Routers aren't the exact same thing (of ... Personal Firewall, I wonder if that program is any good? ... > handled by anti-virus programs, which should be on ... > A NIDS is just that. ...
      (comp.security.firewalls)
    • RE: serial-line protocols
      ... I would think you'd be better off deploying the NIDS at either end instead, ... adjacent to one of the routers. ... > optical-tap with a protocol converter suffice? ... > With a serial-line protocol would any synchronization at the ...
      (Focus-IDS)
    • RE: Use of Taps for IDS
      ... switch), on a full-duplex link I'm looking at INCOMING and OUTGOING ... traffic - two streams. ... the output of my "tap" is going to be two separate physical ... NIDS deployments, you're looking at: ...
      (Focus-IDS)