IPS/IDS location suggestions in Network.



ttp://uploader.futbolmex.net/files/1/network.JPG


See link for Network design, design for redundancy and speed.

these boxes are routers and links are 10gb.

different network segements will be hanging off of the 4 routers at
the bottom.

There will be an IPS higher up in the mix between the 2 top routers
and the internets as well as other stuff.

Main corporate network will be hanging off each of the 4 bottom switches.

So the goal is to monitor internal traffic between 4 network segments.

Idea of Cisco module IDS in the 2 top routers is scratched.

So what about in-line IPS on each of the links between the 4 routers
and the 2?
ISS has the GX6116 that runs at 6gb in filtering mode, 15gb non
filtering, hehe.
Sourcefire just sent me an email about their 10gb solution, but I dont
know if it has as many ports as the ISS box.

Is this even a good location for an inline IPS? It seems like the only
place other than the boarder where I can get any concentrated traffic,
but at the border I cant get internal traffic.

Any suggestions?

Saludos

Albert

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • RE: FreeBSD router two DSL connections
    ... >> control how traffic goes OUT of your network. ... > filtering is simply wrong. ... el-cheapo DSL routers that are network address translators, ... 7206 VXR's now, any ISP under 10,000 customers can easily ...
    (freebsd-questions)
  • Re: Corporate Intranet
    ... Try to map or figure out how is the network inside... ... all ip addresses involved, specially on routers. ... On internet browsers combined with Social Engineering, ... InfoSec Institute ...
    (Pen-Test)
  • Re: Makes no sense to me?
    ... A NIC by itself cannot "join two routers". ... > What I think you want is to have two NICs in EACH server. ... > One NIC on each server connects to a corresponding router and nothing else. ... > shared switch defined on a third IP network ...
    (microsoft.public.win2000.networking)
  • Re: Users cant see past 2nd nic to connect to internet - new sbs
    ... "You have 2 routers" ... Right click My Network Places...Properties. ... Ethernet adapter Server Local Area Connection: ... Connection-specific DNS Suffix. ...
    (microsoft.public.windows.server.sbs)
  • Re: College ethernet switch problems
    ... your sys admins of the DHCP servers have found relevant MAC address prefixes for the popular broadband routers and denied them from obtaining IP addresses. ... If your network admins are smart, then can detect all kinds of anomalies like downstream switches/hubs, broadband routers, wireless APs, etc. ... That port fee is probably for one port, and the network in your building may only be designed to support one host or two hosts per room. ... After being pissed my router no longer worked i turned off its DHCP server to, i thought, make it act as a switch. ...
    (comp.dcom.lans.ethernet)

Quantcast