How much "out of band" is enough ?

From: Rainer Duffner (rainer_at_ultra-secure.de)
Date: 02/04/05

  • Next message: Badger, Jared: "RE: How much "out of band" is enough ?"
    Date: Fri, 04 Feb 2005 18:47:24 +0100
    To: focus-ids@securityfocus.com
    
    

    Hello,

    I'd like to know, how the "out of band" management of IDS and related
    SW/HW is done in various environments.

    E.g.: for LAN, is it necessary to use separate switches or are VLANs
    enough ?
    (May depend on the policy).
    And for WAN, do you rent separate leased-lines or is it just another
    VPN-tunnel in the line ?

    Thanks in advance,
    Rainer

    -- 
    ===================================================
    ~     Rainer Duffner - rainer@ultra-secure.de     ~
    ~           Freising - Munich - Germany           ~
    ~    Unix - Linux - BSD - OpenSource - Security   ~
    ~  http://www.ultra-secure.de/~rainer/pubkey.pgp  ~
    ===================================================
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from 
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    --------------------------------------------------------------------------
    

  • Next message: Badger, Jared: "RE: How much "out of band" is enough ?"

    Relevant Pages

    • Re: VM issue causing high CPU loads
      ... I can't guarantee that ... environments where all IDs are consistent, ... you may have lots of non-posix systems. ... numeric IDs to be used? ...
      (Linux-Kernel)
    • RE: Worm attack generation tools
      ... Subject: Worm attack generation tools ... I would assume that the IDS system is "mainly" watching ingress ... Then you're talking LAN speeds. ... Find out quickly and easily by testing it with real-world attacks from CORE ...
      (Focus-IDS)
    • Re: using linux for security at work??
      ... > suggestions for software for sniffing and scanning the LAN would be ... > something of our own for the LAN and Internet, I know of snort, is this ... very good as an IDS. ...
      (comp.os.linux.security)

  • Quantcast