RE: IPS vs Firewall

From: Sanjay K. Patel (sanjay.patel_at_rexwire.com)
Date: 04/30/04

  • Next message: Josh Mills: "RE: Windows SUS"
    To: "'Benny Late'" <lvmygop@hotmail.com>, <security-basics@securityfocus.com>
    Date: Thu, 29 Apr 2004 18:43:22 -0400
    
    

    Your best place to look would be a IPS vendor. All most all them have canned
    e-mails showing exactly what you want to show.

    -Sanjay

    -----Original Message-----
    From: Benny Late [mailto:lvmygop@hotmail.com]
    Sent: Tuesday, April 27, 2004 4:16 PM
    To: security-basics@securityfocus.com
    Subject: IPS vs Firewall

    List,

    I am to give a presentation concerning IPS vs. IDS and why we have decided
    to implement an IPS solution. I have stuff about each of those, but my big
    problem is going to come from my LAN/WAN group. Because I've decided to
    place the IPS outside the firewall, they have already moaned about it and I
    know they're going to bring up why we need IPS vs. Firewall. I have stuff
    about what firewalls don't look for or do compared to IPS.

    My question is, how would you go about showing that firewalls or BigIP
    routers can be attacked directly? For those of you concidering IPS, can you
    impart any of the knowledge gained by implementing your solutions?

    Many thanks,
    Benny

    _________________________________________________________________
    >From must-see cities to the best beaches, plan a getaway with the
    >Spring
    Travel Guide! http://special.msn.com/local/springtravel.armx

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the
    skills of an Ethical Hacker to better assess the security of your
    organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: Josh Mills: "RE: Windows SUS"

    Relevant Pages

    • Re: Analysing and configuring IPS/IDS Policies
      ... If you have no faith in the firewall or you are concerned about more ... Remove the IPS from the network. ... policies and logs on those devices. ...
      (Focus-IDS)
    • RE: IPS (was: [fw-wiz] Sources for Extranet Designs?)
      ... IPS has been pretty much been expected to weed out the known bad traffics on ... looks for these type of behaviour in a sequence of packets, ... firewall don't make these kind of mistakes. ... decently good ones will go through the trouble of reassembling the packets ...
      (Firewall-Wizards)
    • RE: IPS (was: [fw-wiz] Sources for Extranet Designs?)
      ... it merely does string-matchings on the packets alone. ... Network IPS: ... A software shim (firewall) that sits between the kernel and the application. ... deployed deep inside a network. ...
      (Firewall-Wizards)
    • RE: IPS vs Firewall
      ... Might I suggest using the witty worm as an example? ... > to implement an IPS solution. ... > place the IPS outside the firewall, ... of an Ethical Hacker to better assess the security of your organization. ...
      (Security-Basics)
    • RE: IPS vs Firewall
      ... IDS, IPS, URL screener, NAT built into one box. ... >> Ethical Hacking at the InfoSec Institute. ... > our expert instructors. ... >> Attend a course taught by an expert instructor ...
      (Security-Basics)