Re: IPS and Trunking



The function that you speak of on the Cisco is a feature of the switch itself (called DSPAN), not a feature on the IDS/IPS devices. This feature is common across enterprise-grade switches, and allows for the monitoring of all traffic flowing through the ports on that switch.

IDS (Intrusion Detection) devices typically connect to DSPAN ports to "see" all traffic. This holds true for most (if not all) vendors mentioned.

IPS (Intrusion Prevention) devices ideally connect in-line, between your router and your firewall, blocking all intrusions at the network gateway.


HTH,
Paul



trav_2@xxxxxxxxxxx wrote:
Cisco has a great feature where I can configure all traffic on a switch to go to a trunk port, plug in the IPS/IDS to the trunk port and see all traffic. Can other vendors, such as Sourcefire, TippingPoint, ISS do this?

Thanks,

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more.
------------------------------------------------------------------------



------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more.
------------------------------------------------------------------------



Relevant Pages

  • Re: Does Handling Matter?
    ... the working of the radio/CD player, which has a feature that I do not like. ... Anyhow the feature I don't like is the arrangement whereby I am limited to 30 minutes of radio/CD player usage unless the engine is running. ... Given that I'm retired and very fond of music and the countryside, I used to like to take the car out to a nice spot and settle down to a bit of CD enjoyment or reading. ... The stupidity of it is emphasised when you bear in mind that after 30 minutes the radio/CD player stops working, but I could switch on all the lights and have wipers, washers and electric windows working all afternoon - with no time limit whatsoever on their functioning. ...
    (uk.rec.driving)
  • Re: CASE mis-understanding?
    ... reordering the cases of the switch statement; ... language feature, library feature, or operating system feature. ... That's not a good argument against correcting students' untrue ideas, ... teach anything about the machine level at all (and that includes my ...
    (comp.lang.forth)
  • Re: [RFC] ethtool semantics
    ... I find the c) feature very convenient. ... the configuration of the switch, something which is usually (pick your ... Command line parameters of the bcm5700 driver do implement c) (among ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)
  • Re: CASE mis-understanding?
    ... reordering the cases of the switch statement; ... stuff, including C compiler maintainers. ... feature, library feature, or operating system feature. ... you can't generalize directly from your students to all ...
    (comp.lang.forth)