RE: network segment range which NIDS can detect?

From: Burton M. Strauss III (BStrauss_at_acm.org)
Date: 06/20/03

  • Next message: dave_at_netmedic.net: "RE: DNS Records"
    To: <security-basics@securityfocus.com>
    Date: Thu, 19 Jun 2003 18:38:43 -0500
    
    

    With a switch, the default action if it can't be sure of a specific port to
    use (fail safely) is to send the packet on to all of the ports except the
    one it was received from.

    Too many packets may overwhelm the per port buffers
    Too many MAC addresses for the (usually 1K or 4K) buffer
    True broadcast packets (both MAC and perhaps higher level)

    etc.

    -----Burton

    -----Original Message-----
    From: SB CH [mailto:chulmin2@hotmail.com]
    Sent: Wednesday, June 18, 2003 2:07 AM
    To: security-basics@securityfocus.com
    Subject: network segment range which NIDS can detect?

    Hello, all.

    I installed snort NIDS at my linux which connected at switch and I
    confirmed that snort could detect some other servers were attacked. As I
    know, NIDS can detect some other attacks in the range of a network segment.
    Then what is a "same network segment" in the switch?
    I can detect some attacks to A server, but B isn't which connected with
    same switch.

    Surely, I didnt' use the tab or span at switch.

    Thanks in advance.

    _________________________________________________________________
    Àü¼¼°èÀÎÀÌ ÇÔ²²ÇÏ´Â À¥ ¸ÞÀÏ ¼­ºñ½ºÀÎ MSN HotmailÀ» ¸¸³ª º¸¼¼¿ä.
    http://loginnet.passport.com/login.srf?id=2&svc=mail&cbid=24325&msppjph=1&lc
    =1042

    ---------------------------------------------------------------------------
    Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
    The Gartner Group just put Neoteris in the top of its Magic Quadrant,
    while InStat has confirmed Neoteris as the leader in marketshare.

    Find out why, and see how you can get plug-n-play secure remote access in
    about an hour, with no client, server changes, or ongoing maintenance.

    Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
    The Gartner Group just put Neoteris in the top of its Magic Quadrant,
    while InStat has confirmed Neoteris as the leader in marketshare.
         
    Find out why, and see how you can get plug-n-play secure remote access in
    about an hour, with no client, server changes, or ongoing maintenance.
              
    Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
    ----------------------------------------------------------------------------


  • Next message: dave_at_netmedic.net: "RE: DNS Records"

    Relevant Pages

    • Re: AW: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 618
      ... A *switch* otoh, ... keeps a list of what hardware addresses may be found at what port. ... >> Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ... >> about an hour, with no client, server changes, or ongoing maintenance. ...
      (Security-Basics)
    • Re: Experts Help Please Settle Arguement - Hub or Switch if ISP offers several IPs
      ... you don't use a switch in this kind of arrangement. ... >Switches an algorithim for routing packets at Layer 2. ... >response is sent back to the hub from the right destination node. ... Note that I show an 8 port hub in the top drawing instead of a switch. ...
      (alt.internet.wireless)
    • Re: AW: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 618
      ... port, if it has one. ... That machine would then be able to see all traffic on the switch. ... > Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ... > about an hour, with no client, server changes, or ongoing maintenance. ...
      (Security-Basics)
    • Re: OT: Questions about routers, switches, hubs, etc.
      ... when would I need a switch? ... All the devices connected to it can see all the packets. ... Devices only see the IP addresses that are hooked up to that port. ... Some where the port is directly exposed to the Internet, some behind the firewall (good for protecting computers). ...
      (rec.gambling.poker)
    • Re: Experts Help Please Settle Arguement - Hub or Switch if ISP offers several IPs
      ... Hubs and switches will both work perfectly in this scenario. ... Switches send the minimal amount of traffic to each port. ... you don't use a switch in this kind of arrangement. ... >because it doesn't know where to route packets. ...
      (alt.internet.wireless)