Re: location of an IPS

From: FinAckSyn (finacksyn_at_yahoo.co.uk)
Date: 10/20/05

  • Next message: Madalin Bratu: "RE: Juniper Vs Tipping point, Intrushield and Stonegate"
    Date: Thu, 20 Oct 2005 14:29:28 +0100 (BST)
    To: Doug Fox <dfox168@hotmail.com>, focus-ids@securityfocus.com
    
    

    An IPS should be placed in front of the firewall, to
    provide complete network protection.
    However, the Unity 50 is quite low spec - 5,000
    connections per second, 5,000 concurrent connections.
    Bearing in mind most Check Point firewalls have a
    default connection table size of 40,000 (?)
    connections, then putting the Unity 50 in front of
    your firewall would be a bottleneck.
    Assuming small packet size (512bits per packet), then
    5,000 of these per second equates to just under 3Mbs.
    If your Internet feed is less than this, then no
    problem. If it's higher, then the Unity 50 would not
    be able to handle a 3Mbs pipe full of small packets.
    You should really design your perimeter with this
    worse case scenario in mind, especially if you have
    negotiated burst rates with your ISP and your ISP feed
    can suddenly shoot up in usage.
    Port scans should be blocked by the firewall - all
    irrelevant ports are discarded at this point. I'm not
    sure how the Unity 50 handles port scans, I haven't
    played with one yet... ;)

    Regards,

    Matt

    --- Doug Fox <dfox168@hotmail.com> wrote:

    > I'm sorry for this dumb question, which may have
    > been answered many times.
    >
    > Where should one place an TippingPoint Unity 50 IPS
    > device? Behind or in
    > front of a firewall?
    >
    > I have a/the TippingPoint behind a Check Point
    > firewall. Even though we
    > externally and internally port-scanned the firewall
    > and the IPS many times,
    > the activity log did not contain any record of the
    > "attacks".
    >
    > What am I missing here? Any pointers are
    > appreciated.
    >
    > Thanks,
    >
    >
    ------------------------------------------------------------------------
    > Test Your IDS
    >
    > Is your IDS deployed correctly?
    > Find out quickly and easily by testing it
    > with real-world attacks from CORE IMPACT.
    > Go to
    >
    http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    >
    > to learn more.
    >
    ------------------------------------------------------------------------
    >
    >

                    
    ___________________________________________________________
    To help you stay safe and secure online, we've developed the all new Yahoo! Security Centre. http://uk.security.yahoo.com

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Madalin Bratu: "RE: Juniper Vs Tipping point, Intrushield and Stonegate"

    Relevant Pages

    • Re: location of an IPS
      ... You're assuming each packet is a new connection/etc. ... > connections per second, 5,000 concurrent connections. ... > your firewall would be a bottleneck. ... then the Unity 50 would not ...
      (Focus-IDS)
    • Location of an IPS
      ... Where should I installed a network-based Intrusion Prevention System (IPS)? ... Is it in front of a firewall or behind it? ... The IPS is a Tipping Point Unity 50. ...
      (alt.computer.security)
    • Re: What is the Pattern here ?
      ... These are all Dialup Connections that I had no connection with at the time. ... It's obviously an enormous security hole, ... > and a real firewall box. ...
      (comp.security.firewalls)
    • Re: Analysing and configuring IPS/IDS Policies
      ... If you have no faith in the firewall or you are concerned about more ... Remove the IPS from the network. ... policies and logs on those devices. ...
      (Focus-IDS)
    • Re: Black Ice confesses faulty program!!!
      ... > outgoing connections or traffic except in cases where these connections ... > "dangerous/suspicious" traffic by the BlackICE program. ... > get into your machine then even a PC *without* a firewall is completely ... If you don't think "Spyware" is a problem for computer ...
      (comp.security.firewalls)