Re: IDS causing troubles



On Feb 14, 2011, at 1:28 PM, JiPi DiNi wrote:

If inline it has to be a bypass switch not a tap.

an IPS with a TAP is an IDS.
an IPS with a bypass switch configured inline can block on traffic.

You might want to clarify this statement a bit more, for instance, there are tap vendors that make devices called "Vmode" taps, which is essentially an inline tap, the traffic goes through the tap, and sent through an IPS, however if the IPS fails, the vmode tap "fails open" sending the traffic straight through.

This may be what you meant about a bypass switch, but just clarifying the terminology.


--
Joel Esler
http://www.joelesler.net


-----------------------------------------------------------------
Securing Your Online Data Transfer with SSL.
A guide to understanding SSL certificates, how they operate and their application. By making use of an SSL certificate on your web server, you can securely collect sensitive information online, and increase business by giving your customers confidence that their transactions are safe.
http://www.dinclinx.com/Redirect.aspx?36;5001;25;1371;0;1;946;9a80e04e1a17f194



Relevant Pages

  • RE: IDS causing troubles
    ... Security Architect ... Subject: IDS causing troubles ... an IPS with a bypass switch configured inline can block on traffic. ... This may be what you meant about a bypass switch, ...
    (Focus-IDS)
  • Re: IDS causing troubles
    ... plenty of ips systems can do their job ... If inline it has to be a bypass switch not a tap. ... an IPS with a bypass switch configured inline can block on traffic. ...
    (Focus-IDS)
  • RE: Recent Gartner IDS/IPS report
    ... > resources to properly analyze security reports, ... > replace the IDS products. ... since these same vendors compete with your ... Basing IPS entirely on IDS and making the offspring a single product is ...
    (Focus-IDS)
  • RE: IDS alerts / second - Correlation - Virtualization
    ... combinations that operating systems and applications respond improperly ... IDS alerts / second - Correlation - Virtualization ... any IPS has to do IDS first. ...
    (Focus-IDS)
  • RE: IDS alerts / second - Correlation - Virtualization
    ... If you take a proper IPS, and by that I don't mean an IDS that has been ... followed by rate limiting and Layer 4 checks before it ...
    (Focus-IDS)