|
|||||||||||
|
RE: best ids placement?
From: Brian Laing <brian.laing(at)blade-software.com>
Date: Mon Jun 30 2003 - 13:42:09 EDT
With what you are looking at I would not recommend a hub in that possision you are talking about because of the collisions issues, this is magnified if the router to switch connection is full duplex. If your switch supports it you can span the port that goes to the router but you may overload the port, plus spaning packets is low priority in the switch so even if the port is overloaded the swtich may not span all packets. The only thing I have seen that will garuntee or atleast get you as much as can be garunteed is taps with the legs form the taps being fed into a toplayer or similar type of switch. If the load is low enough you can take the two legs from a tap and send them to a hub. You will run into collision issues but it will impact the ids where as the hub placement you have no will impact the network. I hope that makes sense if not drop me a private email.
Cheers,
Brian Laing CTO Blade Software Cellphone: +1 650.280.2389 Telephone: +1 650.367.9376 eFax: +1 650.249.3443 Blade Software - Because Real Attacks Hurt http://www.Blade-Software.com
-----Original Message-----
Hello, all.
I have read this document, subject is "Using Snort For a Distributed
Intrusion Detection System" at
according to this document, the proper placement say like this
The first example of the remote sensor placement is if you have a
high-speed connection
~~~~~~~~~ dummy hub
placement between router and firewall or main switch like this?
router
|
IDS ---------HUB
|
Switch
but another document say like this.
What's the true and how did you set ids placement and what is the best? using taps? or span port? or hub? Thjanks for your opinions. È®ÀÎÇÏÀÚ. ¿À´ÃÀÇ ¿î¼¼ ¹«·á »çÁÖ, ±ÃÇÕ, ÀÛ¸í, Àü»ý °¡À̵å http://www.msn.co.kr/fortune/default.asp --- Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the world's premier technical IT security event! 10 tracks, 15 training sessions, 1,800 delegates from 30 nations including all of the top experts, from CSO's toReceived on Wed Jul 2 10:31:39 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:15 EDT |
||||||||||
|
|||||||||||