RE: IDS in a loadbalanced Network



Jan,

*** I work for ISS ***

This is likely a vendor specific question.

Some vendors can monitor the HSRP traffic directly, while others will
not be able to reliably recognize attacks tunneled within HSRP. If your
vendor cannot identify attacks within HSRP, you would either need to
chose a different location for the IDS where HSRP is not present or
chose another vendor.

Some vendors aggregate the packets from their various adapters, while
others do not. In some cases, they do so only partially. Ask your vendor
whether they support PortChannel, EtherChannel, etc. and how they
support it. If the adapters are aggregated, the best thing would be to
place a tap on each link in the channel/bundle and feed the packets from
all of the links to the same IDS. That is, you would place a tap on each
link and feed the output from each tap to a different input adapter on
the same IDS. If the IDS cannot aggregate adapters, you will need to use
a SPAN port capable of handling the full bandwidth of the channel, look
at placing the IDS elsewhere on the network where PortChannel is not
used, or chose another vendor.

I hope this helps.

Paul

P.S. Since I work for ISS I would be remiss if I did not mention that
ISS products do recognize attacks tunneled within HSRP and do aggregate
the packets from their adapters.

-----Original Message-----
From: Scholten, Jan [mailto:jan.scholten@xxxxxxxxxxx]
Sent: Thursday, September 07, 2006 6:27 AM
To: focus-ids@xxxxxxxxxxxxxxxxx
Subject: IDS in a loadbalanced Network

Hi!

While searching for a matching IDS I encountered some problems.

Having a network structure with lots of seperate Vlans and/or DMZs
networks, i am wondering what is the best way to place an IDS in a
redundant L3Switch/router (C6506/7300) with HSRP and PortChannel
Loadbalancing for Vlans.
Is there a bestpractice how to place an ids in a vlan, using a span port
on each of the devices (running in active/active), or is there a better
solution?

Regards from Germany
Jan Scholten


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708

to learn more.
------------------------------------------------------------------------


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • RE: Intrusion Prevention
    ... Coverage what can it detect; this covers basic attacks, ... IDS purchase. ... While doing these implementations and while working in an IDS vendor I ... sometimes we're told that we cannot see the testing methodology upfront. ...
    (Focus-IDS)
  • RE: Help in evaluating Inline IDS/IPS solution
    ... This really depends on the vendor and the signature. ... Do the IDS vendors claim this? ... support on new attacks and vulnerabilities found. ... INTRUSION PREVENTION: READY FOR PRIME TIME? ...
    (Focus-IDS)
  • Re: IDS in a loadbalanced Network
    ... I'm confused about your comments regarding packets "tunneled within ... HSRP is Cisco's Hot Standby Routing Protocol. ... This is likely a vendor specific question. ... all of the links to the same IDS. ...
    (Focus-IDS)
  • RE: Intrusion Prevention requirements document
    ... This allows for live production systems to be ... to check the configuration of their firewalls, IPS, IDS, routers, switches ... When you brought in each vendor for evaluation, ... Find out quickly and easily by testing it with real-world attacks from CORE ...
    (Pen-Test)
  • RE: IDS testing...again [WAS: Re: (OpenBSD or Linux)]
    ... Subject: IDS testing...again ... How come vendor Y wasn't in there? ... I think the Mier tests left me with more questions then answers. ... This has been debated quite a bit on this (and other lists) in the past. ...
    (Focus-IDS)