RE: location of an IPS

From: Swift, David (dswift_at_ipolicynetworks.com)
Date: 10/20/05

  • Next message: Paul Schmehl: "Re: TippingPoint and its filters"
    Date: Thu, 20 Oct 2005 07:23:06 -0700
    To: "Doug Fox" <dfox168@hotmail.com>, <focus-ids@securityfocus.com>
    
    

    Where to put an IPS depends on your network and what you want to do with
    it.

    Most IPS's need L2 connectivity to a LAN segment if you want to monitor
    it. So...if your looking to monitor internal traffic, it will sit south
    (protected side) of your firewall. At L3/Routing, an alternate path not
    through the device (or dropping of broadcasts), may prevent the IPS from
    seeing the attack.

    Likewise you may have VPN termination on the firewall, and an IPS cannot
    detect events in encrypted traffic streams (unless it is the VPN
    termination point itself), so the device may be installed south of the
    VPN concentrator.

    Alternatively however, since most IPS boxes can also do DoS and DDoS
    mitigation, you may want it north (unprotected side) of your firewall to
    help screen/drop DoS/DDoS attacks.

    -----Original Message-----
    From: Doug Fox [mailto:dfox168@hotmail.com]
    Sent: Wednesday, October 19, 2005 3:58 PM
    To: focus-ids@securityfocus.com
    Subject: location of an IPS

    I'm sorry for this dumb question, which may have been answered many
    times.

    Where should one place an TippingPoint Unity 50 IPS device? Behind or
    in
    front of a firewall?

    I have a/the TippingPoint behind a Check Point firewall. Even though we
    externally and internally port-scanned the firewall and the IPS many
    times,
    the activity log did not contain any record of the "attacks".

    What am I missing here? Any pointers are appreciated.

    Thanks,

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708

    to learn more.
    ------------------------------------------------------------------------

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Paul Schmehl: "Re: TippingPoint and its filters"

    Relevant Pages

    • Re: Nortel Contivity 2600
      ... I would still put the outside interface of the VPN device behind an in-line IPS ... otherwise you could still be vulnerable to DoS attacks (IKE ... >> for vulnerabilities ...
      (Pen-Test)
    • Re: Should a firewall ONLY allow access to an IP range - as well as blocking ports?
      ... > ports - we can and know how to restrict this to only allowed IPs but the ... take a vpn client. ... such as SecurID tokens - this is because even if the securID token is stolen ... he is allowed to do (determined by the firewall rulebase). ...
      (comp.security.misc)
    • Re: Should a firewall ONLY allow access to an IP range - as well as blocking ports?
      ... > ports - we can and know how to restrict this to only allowed IPs but the ... take a vpn client. ... such as SecurID tokens - this is because even if the securID token is stolen ... he is allowed to do (determined by the firewall rulebase). ...
      (comp.security.firewalls)
    • Re: Should a firewall ONLY allow access to an IP range - as well as blocking ports?
      ... > ports - we can and know how to restrict this to only allowed IPs but the ... take a vpn client. ... such as SecurID tokens - this is because even if the securID token is stolen ... he is allowed to do (determined by the firewall rulebase). ...
      (alt.computer.security)
    • RE: Sessions Resource Exhaustion
      ... Please read the definition of DoS Attacks. ... I believe any firewall will be a victim if we setup a test launching ... IPS can take care of many of these but an attacker can still modify ... Subject: Sessions Resource Exhaustion ...
      (Focus-IDS)